Bug#1143062: trafficserver: CVE-2026-22068 CVE-2026-24033 CVE-2026-33267 CVE-2026-33930 CVE-2026-41920 CVE-2026-57834 CVE-2026-58150 CVE-2026-58151 CVE-2026-58152 CVE-2026-58153 CVE-2026-58154 CVE-2026-58155 CVE-2026-58156 CVE-2026-58157 CVE-2026-58158 CVE-2026-58159 CVE-2026-58160 CVE-2026-58161 CVE-2026-58162 CVE-2026-58163 CVE-2026-58164 CVE-2026-58175 CVE-2026-58177 CVE-2026-58178 CVE-2026-58179 CVE-2026-58180 CVE-2026-58181 CVE-2026-58182 CVE-2026-58183 CVE-2026-58184 CVE-2026-58185 CVE-2026-58186 CVE-2026-58187 CVE-2026-58188 CVE-2026-58189 CVE-2026-65100 CVE-2026-65324 CVE-2026-65325
Salvatore Bonaccorso <[email protected]>
| Newsgroups | gmane.linux.debian.devel.bugs.rc |
|---|---|
| Message-ID | <[email protected]> |
Source: trafficserver Version: 9.2.5+ds-1 Severity: grave Tags: security upstream Justification: user security hole X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]> Hi, The following vulnerabilities were published for trafficserver. CVE-2026-22068[0]: | Regular Expression without Anchors vulnerability in Apache Traffic | Server. This issue affects Apache Traffic Server: from 10.0.X | through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to | upgrade to version 9.2.15 or 10.1.4, which fixes the issue. CVE-2026-24033[1]: | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response | Smuggling') vulnerability in Apache Traffic Server. This issue | affects Apache Traffic Server: from 10.0.0 through 10.1.3, from | 9.0.0 through 9.2.14. Users are recommended to upgrade to version | 9.2.15 or 10.1.4, which fixes the issue. CVE-2026-33267[2]: | Improper Input Validation vulnerability in Apache Traffic Server. | This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, | from 10.1.0 through 10.1.3. Users are recommended to upgrade to | version 9.2.15 or 10.1.4, which fixes the issue. CVE-2026-33930[3]: | Apache Traffic Server copies the client Host header into a fixed- | size stack buffer without a bound during redirect handling, so an | over-long Host header overflows the stack when redirect following is | enabled. This issue affects Apache Traffic Server: from 8.0.0 | through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through | 10.1.3. Users are recommended to upgrade to version 9.2.15 or | 10.1.4, which fix the issue. CVE-2026-41920[4]: | Improper Access Control vulnerability in Apache Traffic Server. | This issue affects Apache Traffic Server: from 9.0.0 through 9.1.14, | from 10.0.0 through 10.1.3. Users are recommended to upgrade to | version 9.1.15 or 10.1.4, which fixes the issue. CVE-2026-57834[5]: | Apache Traffic Server allows request smuggling if chunked messages | are malformed. This issue affects Apache Traffic Server: from 8.0.0 | through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through | 10.1.3. Users are recommended to upgrade to version 9.2.15 or | 10.1.4, which fix the issue. CVE-2026-58150[6]: | Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 | requests, allowing downgrade request smuggling. This issue affects | Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through | 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to | upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58151[7]: | Apache Traffic Server can be crashed or driven to resource | exhaustion by abusive HTTP/2 framing and flow-control. This issue | affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 | through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended | to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58152[8]: | Apache Traffic Server mishandles integers while decoding HPACK/XPACK | headers, corrupting memory. This issue affects Apache Traffic | Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from | 10.0.0 through 10.1.3. Users are recommended to upgrade to version | 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58153[9]: | Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 | clients without proper chunked framing when converting HTTP/2 to | HTTP/1. This issue affects Apache Traffic Server: from 10.0.0 | through 10.1.3. Users are recommended to upgrade to version 9.2.15 | or 10.1.4, which fix the issue. CVE-2026-58154[10]: | Apache Traffic Server can write out of bounds or overflow integers | while parsing MIME and HTTP headers. This issue affects Apache | Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, | from 10.0.0 through 10.1.3. Users are recommended to upgrade to | version 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58155[11]: | Apache Traffic Server truncates over-long header names, allowing | header aliasing, request smuggling, and policy bypass. This issue | affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 | through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended | to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58156[12]: | Apache Traffic Server mis-parses ports in URLs and userinfo, | allowing port-based access-control bypass. This issue affects | Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through | 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to | upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58157[13]: | Apache Traffic Server can reuse server sessions and tunnels | improperly, exposing data across client connections. This issue | affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 | through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended | to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58158[14]: | Apache Traffic Server mishandles PROXY protocol input, truncating | ports and overflowing the stack. This issue affects Apache Traffic | Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from | 10.0.0 through 10.1.3. Users are recommended to upgrade to version | 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58159[15]: | Apache Traffic Server can bypass IP access controls on UDS listeners | and through ACL matching errors. This issue affects Apache Traffic | Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from | 10.0.0 through 10.1.3. Users are recommended to upgrade to version | 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58160[16]: | Apache Traffic Server reads out of bounds while parsing DNS answers. | This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, | from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are | recommended to upgrade to version 9.2.15 or 10.1.4, which fix the | issue. CVE-2026-58161[17]: | Apache Traffic Server can crash from null dereferences and dangling | references in TLS and SNI handling. This issue affects Apache | Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, | from 10.0.0 through 10.1.3. Users are recommended to upgrade to | version 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58162[18]: | The Apache Traffic Server certifier plugin generates certificates | based on attacker-controlled client SNI. This issue affects Apache | Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, | from 10.0.0 through 10.1.3. Users are recommended to upgrade to | version 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58163[19]: | Apache Traffic Server mishandles on-disk cache fields and object | lifetimes, corrupting state or crashing. This issue affects Apache | Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, | from 10.0.0 through 10.1.3. Users are recommended to upgrade to | version 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58164[20]: | Apache Traffic Server has use-after-free and time-of-check/time-of- | use errors in remap configuration handling. This issue affects | Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through | 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to | upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58175[21]: | Apache Traffic Server leaks memory when handling HostDB SRV records. | This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, | from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are | recommended to upgrade to version 9.2.15 or 10.1.4, which fix the | issue. CVE-2026-58177[22]: | The Apache Traffic Server Cripts framework has out-of-bounds writes, | path traversal, and use-after-free errors. This issue affects | Apache Traffic Server: from 10.0.0 through 10.1.3. Users are | recommended to upgrade to version 10.1.4, which fix the issue. CVE-2026-58178[23]: | The Apache Traffic Server ESI plugin can recurse without bound and | fetch attacker-controlled URLs. This issue affects Apache Traffic | Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from | 10.0.0 through 10.1.3. Users are recommended to upgrade to version | 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58179[24]: | The Apache Traffic Server regex_remap plugin overflows the stack and | integers from substitution input. This issue affects Apache Traffic | Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from | 10.0.0 through 10.1.3. Users are recommended to upgrade to version | 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58180[25]: | The Apache Traffic Server txn_box plugin overflows the stack from | attacker-controlled input. This issue affects Apache Traffic | Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from | 10.0.0 through 10.1.3. Users are recommended to upgrade to version | 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58181[26]: | The Apache Traffic Server uri_signing and url_sig plugins can | exhaust the stack or crash on attacker input. This issue affects | Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through | 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to | upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58182[27]: | The Apache Traffic Server ts_lua plugin mishandles initialization, | transform context, and per-instance state. This issue affects | Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through | 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to | upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58183[28]: | The Apache Traffic Server prefetch plugin can crash when processing | attacker-influenced input. This issue affects Apache Traffic | Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from | 10.0.0 through 10.1.3. Users are recommended to upgrade to version | 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58184[29]: | The Apache Traffic Server header_rewrite plugin can crash or corrupt | memory during cookie operations and CIDR condition matching. This | issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from | 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are | recommended to upgrade to version 9.2.15 or 10.1.4, which fix the | issue. CVE-2026-58185[30]: | The Apache Traffic Server intercept plugin has a use-after-free. | This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, | from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are | recommended to upgrade to version 9.2.15 or 10.1.4, which fix the | issue. CVE-2026-58186[31]: | The Apache Traffic Server webp_transform plugin can decode unsafely | and serve mislabeled, cacheable responses. This issue affects | Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through | 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to | upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58187[32]: | The Apache Traffic Server multiplexer plugin overruns its chunk- | decode buffer on upstream input, enabling denial of service. This | issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from | 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are | recommended to upgrade to version 9.2.15 or 10.1.4, which fix the | issue. CVE-2026-58188[33]: | Several Apache Traffic Server experimental plugins have memory- | safety and limit-bypass errors. This issue affects Apache Traffic | Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from | 10.0.0 through 10.1.3. Users are recommended to upgrade to version | 9.2.15 or 10.1.4, which fix the issue. CVE-2026-58189[34]: | Apache Traffic Server allows redirect-limit bypass when plugins | reset the retry counter, enabling SSRF amplification. This issue | affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 | through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended | to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVE-2026-65100[35]: | Apache Traffic Server updates the HTTP/2 HPACK dynamic table before | confirming the header block encoded successfully, so an encode | failure leaves the encoder out of sync with the peer decoder and | corrupts subsequent header blocks on the connection. This issue | affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 | through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended | to upgrade to version 9.2.15 or 10.1.4, which fix the issue. CVE-2026-65324[36]: | Apache Traffic Server drops the per-stream buffer cap when | dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust | server memory. This issue affects Apache Traffic Server: from 8.0.0 | through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through | 10.1.3. Users are recommended to upgrade to version 9.2.15 or | 10.1.4, which fix the issue. CVE-2026-65325[37]: | Apache Traffic Server reuses multiplexed HTTP/2 origin connections | without verifying the server certificate covers the new request | hostname. This issue affects Apache Traffic Server: from 9.0.0 | through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended | to upgrade to version 9.2.15 or 10.1.4, which fix the issue. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-22068 https://www.cve.org/CVERecord?id=CVE-2026-22068 [1] https://security-tracker.debian.org/tracker/CVE-2026-24033 https://www.cve.org/CVERecord?id=CVE-2026-24033 [2] https://security-tracker.debian.org/tracker/CVE-2026-33267 https://www.cve.org/CVERecord?id=CVE-2026-33267 [3] https://security-tracker.debian.org/tracker/CVE-2026-33930 https://www.cve.org/CVERecord?id=CVE-2026-33930 [4] https://security-tracker.debian.org/tracker/CVE-2026-41920 https://www.cve.org/CVERecord?id=CVE-2026-41920 [5] https://security-tracker.debian.org/tracker/CVE-2026-57834 https://www.cve.org/CVERecord?id=CVE-2026-57834 [6] https://security-tracker.debian.org/tracker/CVE-2026-58150 https://www.cve.org/CVERecord?id=CVE-2026-58150 [7] https://security-tracker.debian.org/tracker/CVE-2026-58151 https://www.cve.org/CVERecord?id=CVE-2026-58151 [8] https://security-tracker.debian.org/tracker/CVE-2026-58152 https://www.cve.org/CVERecord?id=CVE-2026-58152 [9] https://security-tracker.debian.org/tracker/CVE-2026-58153 https://www.cve.org/CVERecord?id=CVE-2026-58153 [10] https://security-tracker.debian.org/tracker/CVE-2026-58154 https://www.cve.org/CVERecord?id=CVE-2026-58154 [11] https://security-tracker.debian.org/tracker/CVE-2026-58155 https://www.cve.org/CVERecord?id=CVE-2026-58155 [12] https://security-tracker.debian.org/tracker/CVE-2026-58156 https://www.cve.org/CVERecord?id=CVE-2026-58156 [13] https://security-tracker.debian.org/tracker/CVE-2026-58157 https://www.cve.org/CVERecord?id=CVE-2026-58157 [14] https://security-tracker.debian.org/tracker/CVE-2026-58158 https://www.cve.org/CVERecord?id=CVE-2026-58158 [15] https://security-tracker.debian.org/tracker/CVE-2026-58159 https://www.cve.org/CVERecord?id=CVE-2026-58159 [16] https://security-tracker.debian.org/tracker/CVE-2026-58160 https://www.cve.org/CVERecord?id=CVE-2026-58160 [17] https://security-tracker.debian.org/tracker/CVE-2026-58161 https://www.cve.org/CVERecord?id=CVE-2026-58161 [18] https://security-tracker.debian.org/tracker/CVE-2026-58162 https://www.cve.org/CVERecord?id=CVE-2026-58162 [19] https://security-tracker.debian.org/tracker/CVE-2026-58163 https://www.cve.org/CVERecord?id=CVE-2026-58163 [20] https://security-tracker.debian.org/tracker/CVE-2026-58164 https://www.cve.org/CVERecord?id=CVE-2026-58164 [21] https://security-tracker.debian.org/tracker/CVE-2026-58175 https://www.cve.org/CVERecord?id=CVE-2026-58175 [22] https://security-tracker.debian.org/tracker/CVE-2026-58177 https://www.cve.org/CVERecord?id=CVE-2026-58177 [23] https://security-tracker.debian.org/tracker/CVE-2026-58178 https://www.cve.org/CVERecord?id=CVE-2026-58178 [24] https://security-tracker.debian.org/tracker/CVE-2026-58179 https://www.cve.org/CVERecord?id=CVE-2026-58179 [25] https://security-tracker.debian.org/tracker/CVE-2026-58180 https://www.cve.org/CVERecord?id=CVE-2026-58180 [26] https://security-tracker.debian.org/tracker/CVE-2026-58181 https://www.cve.org/CVERecord?id=CVE-2026-58181 [27] https://security-tracker.debian.org/tracker/CVE-2026-58182 https://www.cve.org/CVERecord?id=CVE-2026-58182 [28] https://security-tracker.debian.org/tracker/CVE-2026-58183 https://www.cve.org/CVERecord?id=CVE-2026-58183 [29] https://security-tracker.debian.org/tracker/CVE-2026-58184 https://www.cve.org/CVERecord?id=CVE-2026-58184 [30] https://security-tracker.debian.org/tracker/CVE-2026-58185 https://www.cve.org/CVERecord?id=CVE-2026-58185 [31] https://security-tracker.debian.org/tracker/CVE-2026-58186 https://www.cve.org/CVERecord?id=CVE-2026-58186 [32] https://security-tracker.debian.org/tracker/CVE-2026-58187 https://www.cve.org/CVERecord?id=CVE-2026-58187 [33] https://security-tracker.debian.org/tracker/CVE-2026-58188 https://www.cve.org/CVERecord?id=CVE-2026-58188 [34] https://security-tracker.debian.org/tracker/CVE-2026-58189 https://www.cve.org/CVERecord?id=CVE-2026-58189 [35] https://security-tracker.debian.org/tracker/CVE-2026-65100 https://www.cve.org/CVERecord?id=CVE-2026-65100 [36] https://security-tracker.debian.org/tracker/CVE-2026-65324 https://www.cve.org/CVERecord?id=CVE-2026-65324 [37] https://security-tracker.debian.org/tracker/CVE-2026-65325 https://www.cve.org/CVERecord?id=CVE-2026-65325 Regards, Salvatore