
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-58189 is a Server-Side Request Forgery (SSRF) amplification vulnerability in Apache Traffic Server caused by a redirect-limit bypass when plugins reset the retry counter. It affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. The vulnerability was published on July 29, 2026. It carries a CVSS v3.1 base score of 7.5 (High) and a CVSS v4.0 base score of 8.2 (High) (GitHub Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-918 (Server-Side Request Forgery), where Apache Traffic Server fails to properly enforce redirect limits when a plugin resets the internal retry counter (GitHub Advisory). By manipulating the retry counter through plugin interactions, an unauthenticated remote attacker can cause the proxy to follow an unbounded number of redirects, effectively amplifying SSRF requests. The attack requires no privileges or user interaction, but does require specific deployment conditions (Attack Requirements: Present in CVSS v4.0), such as a plugin being configured that exposes the retry counter reset capability (GitHub Advisory). No public proof-of-concept code has been identified at this time (Apache Mailing List).
Successful exploitation primarily results in a Denial of Service (DoS) against the vulnerable Apache Traffic Server instance, with high availability impact on the vulnerable system and low availability impact on subsequent systems (GitHub Advisory). There is no direct confidentiality or integrity impact on the vulnerable system itself. However, the SSRF amplification aspect means the server can be weaponized to generate large volumes of requests to internal or external targets, potentially exhausting resources or enabling reconnaissance of internal network services (Red Hat Bugzilla).
There is currently no evidence of public proof-of-concept exploit code or active in-the-wild exploitation (Apache Mailing List). The vulnerability is marked as automatable by NVD SSVC assessment, meaning exploitation could be scripted at scale. The EPSS score is approximately 0.38–0.49%, placing it around the 40th percentile for exploitation probability within 30 days (GitHub Advisory). The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no threat actor attribution has been reported. Detection coverage exists via Nessus plugins (IDs 330728, 333031, 333156).
Apache Software Foundation recommends upgrading Apache Traffic Server to version 9.2.15 or 10.1.4, which contain fixes for this vulnerability (GitHub Advisory, Apache Mailing List). No patched release is available for the 8.x branch; operators running versions 8.0.0–8.1.9 should review and restrict plugin functionality that can reset retry counters, implement network-level controls to limit SSRF attack vectors, and consider migrating to a supported branch. Monitoring for unusual redirect patterns in proxy logs is also advised as a compensating control.
The vulnerability received standard coverage from security aggregators and vulnerability databases shortly after disclosure on July 29, 2026, including entries on VulnDB, CVEFeed, and INCIBE-CERT (Apache Mailing List). A CISA vulnerability bulletin (SB26-215) referenced the issue, and Tenable released Nessus detection plugins. No notable researcher commentary or significant social media discussion beyond routine CVE tracking has been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."