CVE-2026-58186
Apache Traffic Server vulnerability analysis and mitigation

Overview

CVE-2026-58186 is an improper input validation vulnerability in the Apache Traffic Server webp_transform plugin that allows the plugin to decode WebP images unsafely and serve mislabeled, cacheable responses. It affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The vulnerability was published on July 29, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is improper input validation (CWE-20) in the webp_transform plugin bundled with Apache Traffic Server. When processing WebP image requests, the plugin performs unsafe decoding of malformed or crafted WebP content, and additionally serves responses with incorrect content-type labels that are marked as cacheable. An unauthenticated, remote attacker can send specially crafted WebP image requests over the network with no privileges or user interaction required; the attack does require certain deployment conditions (Attack Requirements: Present in CVSS v4.0), such as the webp_transform plugin being enabled (GitHub Advisory, Apache Mailing List).

Impact

Successful exploitation results in a denial of service — an unauthenticated network attacker can crash or degrade the availability of the Apache Traffic Server instance by triggering unsafe WebP decoding. There is no impact to confidentiality or integrity of data. The mislabeled, cacheable responses may also cause downstream cache poisoning effects, potentially serving incorrect content to clients proxied through the affected ATS instance (GitHub Advisory, Red Hat Bugzilla).

Exploitability

No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation at this time. The vulnerability is automatable (no authentication or user interaction required) once the webp_transform plugin is active. The EPSS score is approximately 0.37–0.545%, placing it in the 43rd percentile for exploitation likelihood within 30 days. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Apache Traffic Server instances with the webp_transform plugin enabled, using tools like Shodan or Censys to find ATS deployments running versions 8.0.0–8.1.9, 9.0.0–9.2.14, or 10.0.0–10.1.3.
  2. Craft malformed WebP payload: Construct a specially crafted, malformed WebP image file designed to trigger unsafe decoding behavior in the webp_transform plugin (e.g., invalid header fields, oversized chunks, or malformed bitstream data).
  3. Send HTTP request: Submit an HTTP request to the target ATS instance requesting the malformed WebP resource, ensuring the request is routed through the webp_transform plugin (e.g., by targeting a URL pattern or content type that activates the plugin).
  4. Trigger crash/DoS: The plugin attempts to decode the malformed WebP content unsafely, potentially causing a crash, memory corruption, or resource exhaustion that degrades or terminates the ATS service (GitHub Advisory, Apache Mailing List).

Indicators of compromise

  • Network: Unusual or repeated HTTP requests for WebP image resources (.webp URLs or Accept: image/webp headers) from a single or rotating source IP, particularly with malformed or oversized payloads.
  • Logs: Apache Traffic Server access logs showing a spike in requests to WebP-served endpoints followed by connection resets or 5xx error responses; error logs showing plugin crashes or segmentation faults related to webp_transform.
  • Process: Unexpected termination or restart of the traffic_server process; core dump files generated in the ATS working directory following WebP processing events.

Mitigation and workarounds

Users should upgrade Apache Traffic Server to version 9.2.15 or 10.1.4, which contain fixes for this vulnerability. The 8.x branch does not have a patched release listed; users on 8.x should consider upgrading to a supported branch. As an immediate workaround if patching is not possible, disable the webp_transform plugin in the ATS plugin configuration to eliminate the attack surface (GitHub Advisory, Apache Mailing List, Red Hat Bugzilla).

Community reactions

The vulnerability was reported via the Apache Security mailing list and tracked by Red Hat's Product Security team (OSIDB). No notable independent researcher commentary or significant social media discussion has been identified beyond standard CVE aggregator coverage. The CISA Vulnerability Bulletin (SB26-215) included this CVE in its weekly summary (CISA Bulletin).

Additional resources


SourceThis report was generated using AI

Related Apache Traffic Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-58188HIGH8.4
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver
NoYesJul 29, 2026
CVE-2026-58189HIGH8.2
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver
NoYesJul 29, 2026
CVE-2026-58186HIGH8.2
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver
NoYesJul 29, 2026
CVE-2026-65100MEDIUM6.3
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver-devel
NoYesJul 29, 2026
CVE-2026-58187MEDIUM6.3
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver9
NoYesJul 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management