Critical severity10.0NVD Advisory· Published Jul 29, 2026· Updated Aug 3, 2026
CVE-2026-58150
CVE-2026-58150
Description
Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected products
2from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3+ 1 more
- (no CPE)range: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3
- cpe:2.3:a:apache:traffic_server:*:*:*:*:*:*:*:*range: >=8.0.0,<=8.1.9
Patches
Vulnerability mechanics
References
1- lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6dnvdVendor AdvisoryMailing List
News mentions
1- Apache Traffic Server: 25 Vulnerabilities Disclosed Together on July 30, 2026Vypr Intelligence · Jul 30, 2026