


Perceptive Security
SOC/SIEM Consultancy

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.
This issue affects Apache Traffic Server: from 8.0.0…
Published:
28 July 2026 at 22:00:00
Alert date:
29 July 2026 at 11:00:56
Source:
nvd.nist.gov
Network Infrastructure, Web Technologies
CVE-2026-58162 affects the Apache Traffic Server certifier plugin, which generates TLS certificates based on attacker-controlled client Server Name Indication (SNI) values. This flaw allows an attacker to potentially manipulate certificate generation, posing a significant security risk. The vulnerability spans multiple major version branches: 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Apache has released patched versions 9.2.15 and 10.1.4 to address the issue. Users are strongly recommended to upgrade to these fixed versions immediately. The issue originates from insufficient validation of client-supplied SNI data within the certifier plugin.
Technical details
Mitigation steps:
Affected products:
Apache Traffic Server 8.0.0-8.1.9
Apache Traffic Server 9.0.0-9.2.14
Apache Traffic Server 10.0.0-10.1.3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-58162
https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
