top of page
perceptive_background_267k.jpg

The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.

This issue affects Apache Traffic Server: from 8.0.0…

Published:

29 July 2026 at 00:00:00

Alert date:

29 July 2026 at 13:00:56

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Web Technologies

CVE-2026-58162 affects the Apache Traffic Server certifier plugin, which generates TLS certificates based on attacker-controlled client Server Name Indication (SNI) values. This flaw allows an attacker to potentially manipulate certificate generation, posing a significant security risk. The vulnerability spans multiple major version branches: 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Apache has released patched versions 9.2.15 and 10.1.4 to address the issue. Users are strongly recommended to upgrade to these fixed versions immediately. The issue originates from insufficient validation of client-supplied SNI data within the certifier plugin.

Technical details

Mitigation steps:

Affected products:

Apache Traffic Server 8.0.0-8.1.9
Apache Traffic Server 9.0.0-9.2.14
Apache Traffic Server 10.0.0-10.1.3

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page