CVE-2026-58177
published 2026-07-29CVE-2026-58177: The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This issue affects Apache Traffic Server: from…
PriorityP262critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.59%
45.9th percentile
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 10.1.4, which fix the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | traffic_server | >= 10.0.0 < 10.1.4 | 10.1.4 |
| apache_software_foundation | apache_traffic_server | 10.0.0 – 10.1.3 | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.3HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:L/VA:H/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache Traffic Server up to 10.1.3 use after free (Nessus ID 333156)
vuldb·2026-08-07·CVSS 9.8
CVE-2026-58177 [CRITICAL] Apache Traffic Server up to 10.1.3 use after free (Nessus ID 333156)
A vulnerability marked as very critical has been reported in Apache Traffic Server up to 10.1.3. The affected element is an unknown function. This manipulation causes use after free.
This vulnerability is registered as CVE-2026-58177. Remote exploitation of the attack is possible. No exploit is available.
It is suggested to upgrade the affected component.
GHSA
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.
ghsa_unreviewed·2026-07-29
CVE-2026-58177 [HIGH] CWE-787 The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 10.1.4, which fix the issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-58177 Apache Traffic Server: memory-safety and path-traversal errors in the Cripts framework
bugzilla·2026-07-29·CVSS 8.1
CVE-2026-58177 [HIGH] CVE-2026-58177 Apache Traffic Server: memory-safety and path-traversal errors in the Cripts framework
CVE-2026-58177 Apache Traffic Server: memory-safety and path-traversal errors in the Cripts framework
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 10.1.4, which fix the issue.
Bugzilla
CVE-2026-58177 trafficserver: memory-safety and path-traversal errors in the Cripts framework [fedora-all]
bugzilla·2026-07-29·CVSS 8.1
CVE-2026-58177 [HIGH] CVE-2026-58177 trafficserver: memory-safety and path-traversal errors in the Cripts framework [fedora-all]
CVE-2026-58177 trafficserver: memory-safety and path-traversal errors in the Cripts framework [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 10.1.4, which fix the issue.
Discussion:
FEDORA-2026-5bec7441bb (trafficserver-10.1.4-1.fc44) has been submitted as an update to Fedora 44.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-5bec7441bb
2026-07-29
Published