High severity8.2NVD Advisory· Published Jul 29, 2026· Updated Aug 5, 2026
CVE-2026-22068
CVE-2026-22068
Description
Regular Expression without Anchors vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
Affected products
2from 10.0.X through 10.1.3, from 9.0.X through 9.2.14+ 1 more
- (no CPE)range: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14
- cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*range: >=9.0.0,<9.2.15
Patches
Vulnerability mechanics
References
1- lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6dnvdMailing ListVendor Advisory
News mentions
0No linked articles in our index yet.