CVE-2025-58136
published 2026-04-02CVE-2025-58136: A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0…
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.67%
48.0th percentile
A bug in POST request handling causes a crash under a certain condition.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12.
Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue.
A workaround for older versions is to set proxy.config.http.request_buffer_enabled to 0 (the default value is 0).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | traffic_server | >= 10.0.0 < 10.1.2 | 10.1.2 |
| apache | traffic_server | >= 9.0.0 < 9.2.13 | 9.2.13 |
| apache_software_foundation | apache_traffic_server | 10.0.0 – 10.1.1 | — |
| apache_software_foundation | apache_traffic_server | 9.0.0 – 9.2.12 | — |
| debian | trafficserver | < trafficserver 9.2.5+ds-0+deb12u4 (bookworm) | trafficserver 9.2.5+ds-0+deb12u4 (bookworm) |
| yiisoft | yii2 | >= 0 < 2.0.52 | 2.0.52 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ghsa9.1CRITICAL
osv7.5HIGH
cisa9.8CRITICAL
vendor_debian7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-58136: (A bug in POST request handling causes a crash under a certain conditio
osv·2026-04-03·CVSS 7.5
CVE-2025-58136 [HIGH] CVE-2025-58136: (A bug in POST request handling causes a crash under a certain conditio
(A bug in POST request handling causes a crash under a certain conditio ...)
OSV
CVE-2025-58136: A bug in POST request handling causes a crash under a certain condition
osv·2026-04-02·CVSS 7.5
CVE-2025-58136 [HIGH] CVE-2025-58136: A bug in POST request handling causes a crash under a certain condition
A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue. A workaround for older versions is to set proxy.config.http.request_buffer_enabled to 0 (the default value is 0).
GHSA
GHSA-wvq7-4f7c-q7wc: A bug in POST request handling causes a crash under a certain condition
ghsa_unreviewed·2026-04-02
CVE-2025-58136 [HIGH] CWE-670 GHSA-wvq7-4f7c-q7wc: A bug in POST request handling causes a crash under a certain condition
A bug in POST request handling causes a crash under a certain condition.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12.
Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue.
A workaround for older versions is to set proxy.config.http.request_buffer_enabled to 0 (the default value is 0).
GHSA
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
ghsa·2025-04-10·CVSS 9.1
CVE-2024-58136 [CRITICAL] CWE-424 yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
yiisoft/yii2 Mishandles the Attaching of Behavior Defined by a `__class` Array Key
Yii 2 before 2.0.52 mishandles the attaching of behavior that is defined by an __class array key, a CVE-2024-4990 regression, as exploited in the wild in February through April 2025.
CISA
Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability
cisa·2025-06-02·CVSS 9.8
CVE-2025-35939 [CRITICAL] CWE-472 Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability
Vulnerability: Craft CMS External Control of Assumed-Immutable Web Parameter Vulnerability
Affected: Craft CMS Craft CMS
Craft CMS contains an external control of assumed-immutable web parameter vulnerability. This vulnerability could allow an unauthenticated client to introduce arbitrary values, such as PHP code, to a known local file location on the server. This vulnerability could be chained with CVE-2024-58136 as represented by CVE-2025-32432.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://github.com/craftcms/cms/pull/17220 ; https://nvd.nist.gov/vuln/detail/CVE-2025-35939
Remediation Due Date: 2025-06-23
CISA
Yiiframework Yii Improper Protection of Alternate Path Vulnerability
cisa·2025-05-02·CVSS 9.8
CVE-2024-58136 [CRITICAL] CWE-424 Yiiframework Yii Improper Protection of Alternate Path Vulnerability
Vulnerability: Yiiframework Yii Improper Protection of Alternate Path Vulnerability
Affected: Yiiframework Yii
Yii Framework contains an improper protection of alternate path vulnerability that may allow a remote attacker to execute arbitrary code. This vulnerability could affect other products that implement Yii, including—but not limited to—Craft CMS, as represented by CVE-2025-32432.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. For more information, please see: https://www.yiiframework.com/news/709/please-upgrade-to-yii-2
Debian
CVE-2025-58136: trafficserver - A bug in POST request handling causes a crash under a certain condition. This i...
vendor_debian·2025·CVSS 7.5
CVE-2025-58136 [HIGH] CVE-2025-58136: trafficserver - A bug in POST request handling causes a crash under a certain condition. This i...
A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue. A workaround for older versions is to set proxy.config.http.request_buffer_enabled to 0 (the default value is 0).
Scope: local
bookworm: resolved (fixed in 9.2.5+ds-0+deb12u4)
bullseye: open
sid: open
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-58136 trafficserver: Apache Traffic Server: Denial of Service via POST request handling [fedora-all]
bugzilla·2026-04-03·CVSS 7.5
CVE-2025-58136 [HIGH] CVE-2025-58136 trafficserver: Apache Traffic Server: Denial of Service via POST request handling [fedora-all]
CVE-2025-58136 trafficserver: Apache Traffic Server: Denial of Service via POST request handling [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-2026-7839a46d9d (trafficserver-10.1.2-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-7839a46d9d
Bugzilla
CVE-2025-58136 trafficserver: Apache Traffic Server: Denial of Service via POST request handling [epel-all]
bugzilla·2026-04-03·CVSS 7.5
CVE-2025-58136 [HIGH] CVE-2025-58136 trafficserver: Apache Traffic Server: Denial of Service via POST request handling [epel-all]
CVE-2025-58136 trafficserver: Apache Traffic Server: Denial of Service via POST request handling [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
FEDORA-EPEL-2026-7d17b6d554 (trafficserver-9.2.13-1.el9) has been submitted as an update to Fedora EPEL 9.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-7d17b6d554
---
FEDORA-EPEL-2026-7d17b6d554 (trafficserver-9.2.13-1.el9) has been pushed to the Fedora EPEL 9 stable repository.
If problem still persists, please make note of it in this bug report.
Hackernews
⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
blogs_hackernews·2026-04-13·CVSS 8.6
[HIGH] ⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
Home
Threat Intelligence
Vulnerabilities
Cyber Attacks
Webinars
Expert Insights
Awards
Webinars
Awards
Free eBooks
About THN
Jobs
Advertise with us
## ⚡ Weekly Recap: Fiber Optic Spying, Windows Rootkit, AI Vulnerability Hunting and More
Monday is back, and the weekend’s backlog of chaos is officially hitting the fan. We are tracking a critical zero-day that has been quietly living in your PDFs for months, plus some aggressive state-sponsored meddling in infrastructure that is finally coming to light. It is one of those mornings where the gap between a quiet shift and a full-blown incident response is basically non-existent.
The variety this week is particularly nasty. We have AI models being turned into autonomous exploit engines, North Korean groups playing the long game
Wiz
CVE-2025-58136 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-58136 [HIGH] CVE-2025-58136 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-58136 :
Apache Traffic Server vulnerability analysis and mitigation
A bug in POST request handling causes a crash under a certain condition.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12.
Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue.
A workaround for older versions is to set proxy.config.http.request_buffer_enabled to 0 (the default value is 0).
Source : NVD
## 7.5
Score
Published April 2, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Apache Traffic Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 40
Exploitation Probability (EPSS) 0.2
Affected packages a
Wiz
CVE-2025-65114 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-65114 [HIGH] CVE-2025-65114 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-65114 :
Apache Traffic Server vulnerability analysis and mitigation
Apache Traffic Server allows request smuggling if chunked messages are malformed.
This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1.
Users are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the issue.
Source : NVD
## 7.5
Score
Published April 2, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Apache Traffic Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 37.2
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
trafficserver
cpe:2.3:a:apache:traffic_server
Sources
Debian 11 Severity HIGH No Fix Ad
2026-04-02
Published