CVE-2026-58189
Apache Traffic Server vulnerability analysis and mitigation

Overview

CVE-2026-58189 is a Server-Side Request Forgery (SSRF) amplification vulnerability in Apache Traffic Server caused by a redirect-limit bypass when plugins reset the retry counter. It affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The vulnerability was published on July 29, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The root cause is classified as CWE-918 (Server-Side Request Forgery), where Apache Traffic Server fails to properly enforce redirect limits when a plugin resets the internal retry counter (GitHub Advisory). By manipulating the retry counter through plugin interactions, an unauthenticated remote attacker can cause the proxy to follow an unbounded number of redirects, effectively amplifying SSRF requests. The attack requires no privileges or user interaction, but does require specific deployment conditions (Attack Requirements: Present in CVSS v4.0), such as a plugin being configured that exposes the retry counter reset capability (GitHub Advisory). No public proof-of-concept code has been identified at this time (Apache Mailing List).

Impact

Successful exploitation primarily results in a Denial of Service (DoS) against the vulnerable Apache Traffic Server instance, with high availability impact on the vulnerable system and low availability impact on subsequent systems (GitHub Advisory). There is no direct confidentiality or integrity impact on the vulnerable system itself. However, the SSRF amplification aspect means the server can be weaponized to generate large volumes of requests to internal or external targets, potentially exhausting resources or enabling reconnaissance of internal network services (Red Hat Bugzilla).

Exploitability

There is currently no evidence of public proof-of-concept exploit code or active in-the-wild exploitation (Apache Mailing List). The vulnerability is marked as automatable by NVD SSVC assessment, meaning exploitation could be scripted at scale. The EPSS score is approximately 0.38–0.49%, placing it around the 40th percentile for exploitation probability within 30 days (GitHub Advisory). The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported. Detection coverage exists via Nessus plugins (IDs 330728, 333031, 333156).

Mitigation and workarounds

Apache Software Foundation recommends upgrading Apache Traffic Server to version 9.2.15 or 10.1.4, which contain fixes for this vulnerability (GitHub Advisory, Apache Mailing List). No patched release is available for the 8.x branch; operators running versions 8.0.0–8.1.9 should review and restrict plugin functionality that can reset retry counters, implement network-level controls to limit SSRF attack vectors, and consider migrating to a supported branch. Monitoring for unusual redirect patterns in proxy logs is also advised as a compensating control.

Community reactions

The vulnerability received standard coverage from security aggregators and vulnerability databases shortly after disclosure on July 29, 2026, including entries on VulnDB, CVEFeed, and INCIBE-CERT (Apache Mailing List). A CISA vulnerability bulletin (SB26-215) referenced the issue, and Tenable released Nessus detection plugins. No notable researcher commentary or significant social media discussion beyond routine CVE tracking has been identified.

Additional resources


SourceThis report was generated using AI

Related Apache Traffic Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-58188HIGH8.4
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver
NoYesJul 29, 2026
CVE-2026-58189HIGH8.2
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver
NoYesJul 29, 2026
CVE-2026-58186HIGH8.2
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver
NoYesJul 29, 2026
CVE-2026-65100MEDIUM6.3
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver-devel
NoYesJul 29, 2026
CVE-2026-58187MEDIUM6.3
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver9
NoYesJul 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management