top of page
perceptive_background_267k.jpg

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling.

This issue affects Apache Traffic Server: fro…

Published:

28 July 2026 at 22:00:00

Alert date:

29 July 2026 at 09:01:49

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Web Technologies

A vulnerability in Apache Traffic Server allows HTTP request smuggling via improper handling of Transfer-Encoding headers in HTTP/2 requests. The server fails to reject Transfer-Encoding in HTTP/2 requests, enabling downgrade request smuggling attacks. Affected versions span three major release branches: 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. This type of vulnerability can allow attackers to bypass security controls, poison caches, or hijack requests. Users are strongly recommended to upgrade to the patched versions 9.2.15 or 10.1.4. The issue has been assigned CVE-2026-58150 and is tracked by NVD.

Technical details

Mitigation steps:

Affected products:

Apache Traffic Server 8.0.0-8.1.9
Apache Traffic Server 9.0.0-9.2.14
Apache Traffic Server 10.0.0-10.1.3

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page