CVEFinder.io

CVE-2026-58180

⚠️ high
🔍 Scan for this CVE
Summary

The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

CVSS Score
7.5
High
EPSS Score
0.4
Exploit Probability
Published Date
2026-07-29
First Seen: 2026-07-31
📊 Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 68.5% of all 340,620 vulnerabilities in our database.

#107,155
Above average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Jul 29, 2026
🔍 Exploitation Status
None
No known exploits
⚙️ Automatable
YES
Can be exploited automatically
💥 Technical Impact
Partial
Limited system impact
🏆 Discovered By
Apache Community (reporter)
SSVC data provided by CISA
Last Modified 2026-07-31
Source NVD 🔗
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Vector 4.0 CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE IDs (Weakness Types)

📦 Affected Products 3

🔗 References 1

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-58175 ⚠️ high 7.5 0.4 Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0... 2026-07-29
CVE-2026-58177 ⚠️ high 8.1 0.3 The Apache Traffic Server Cripts framework has out-of-bounds writes, path traversal, and use-after-free errors. This is... 2026-07-29
CVE-2026-58178 ⚠️ high 7.5 0.4 The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects A... 2026-07-29
CVE-2026-58179 ⚠️ high 8.1 0.4 The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input. This issue affec... 2026-07-29
CVE-2026-58181 ⚠️ high 7.5 0.4 The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input. This issue ... 2026-07-29
CVE-2026-58182 ⚠️ high 8.6 0.3 The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issu... 2026-07-29
These CVEs affect the same products