CVE-2025-58136
Apache Traffic Server Analyse et atténuation des vulnérabilités

Aperçu

CVE-2025-58136 is a denial-of-service vulnerability in Apache Traffic Server caused by a bug in POST request handling that triggers a crash under certain conditions. It affects Apache Traffic Server versions 10.0.0 through 10.1.1 and 9.0.0 through 9.2.12. The vulnerability was published on April 2, 2026, and carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory, Apache Mailing List).

Détails techniques

The root cause is classified as CWE-670 (Always-Incorrect Control Flow Implementation), where a code path in POST request handling does not correctly implement the intended algorithm, leading to a crash when that path is traversed under specific conditions. The vulnerability is exploitable remotely over the network with no authentication, no user interaction, and low attack complexity. The bug is specifically triggered when proxy.config.http.request_buffer_enabled is set to a non-default value (non-zero), as the default value of 0 avoids the vulnerable code path (GitHub Advisory, Apache Mailing List).

Impact

Successful exploitation causes Apache Traffic Server to crash, resulting in a denial of service that renders the proxy unavailable to handle legitimate traffic. There is no impact on confidentiality or data integrity — the sole consequence is availability loss. Given that Apache Traffic Server is commonly deployed as a high-performance reverse proxy and CDN component, a crash could disrupt services for large numbers of downstream users (GitHub Advisory).

Étapes d’exploitation

  1. Reconnaissance: Identify internet-facing Apache Traffic Server instances running versions 9.0.0–9.2.12 or 10.0.0–10.1.1 using tools like Shodan or Censys, searching for ATS-specific HTTP response headers.
  2. Verify configuration: Confirm that the target has proxy.config.http.request_buffer_enabled set to a non-zero value, as the default (0) is not vulnerable.
  3. Craft malicious POST request: Construct a specially crafted HTTP POST request that triggers the incorrect control flow path in the request buffer handling logic.
  4. Send the request: Deliver the crafted POST request to the target ATS instance; under the vulnerable condition, the server process crashes, causing a denial of service.
  5. Repeat as needed: Since the crash may cause the process to restart (depending on process supervision configuration), repeated requests may be needed to sustain the denial of service (GitHub Advisory, Apache Mailing List).

Indicateurs de compromis

  • Logs: Unexpected Apache Traffic Server process crash entries or core dump generation in ATS logs (traffic.out, diags.log); repeated process restarts logged by the process supervisor (e.g., systemd, supervisord).
  • Network: Unusual volume of HTTP POST requests to the ATS proxy from a single or small set of source IPs, particularly with malformed or unusual request bodies.
  • Process: Sudden termination of the traffic_server or traffic_manager process; core dump files appearing in the ATS working directory.

Atténuation et solutions de contournement

Users should upgrade Apache Traffic Server to version 10.1.2 (for the 10.x branch) or 9.2.13 (for the 9.x branch), which contain the fix. For systems that cannot be patched immediately, the configuration workaround is to ensure proxy.config.http.request_buffer_enabled is set to 0 — notably, this is already the default value, so systems that have not explicitly changed this setting are not vulnerable. Administrators should audit their ATS configurations to confirm this setting (GitHub Advisory, Apache Mailing List).

Réactions de la communauté

Security news outlets including GBHackers, CyberSecurityNews, and Cyberpress covered the vulnerability alongside other Apache Traffic Server flaws disclosed at the same time, noting the DoS and request smuggling risks (GBHackers, CyberSecurityNews). The vulnerability was also mentioned in The Hacker News weekly recap. Debian and Fedora Linux distributions issued updated packages for trafficserver in response to the disclosure (Linux Security). No notable individual researcher commentary or significant social media discussion beyond standard news aggregation was observed.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté Apache Traffic Server Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-59173HIGH7.5
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver
NonOuiJul 18, 2026
CVE-2025-65114HIGH7.5
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver-debugsource
NonOuiApr 02, 2026
CVE-2025-58136HIGH7.5
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver-debugsource
NonOuiApr 02, 2026
CVE-2025-49763HIGH7.5
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver
NonOuiJun 19, 2025
CVE-2025-31698HIGH7.5
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver-perl
NonOuiJun 19, 2025

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités