top of page
perceptive_background_267k.jpg

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling.

This issue affects Apache Traffic Server: fro…

Published:

28 juli 2026 om 22:00:00

Alert date:

29 juli 2026 om 09:01:49

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Web Technologies

A vulnerability in Apache Traffic Server allows HTTP request smuggling via improper handling of Transfer-Encoding headers in HTTP/2 requests. The server fails to reject Transfer-Encoding in HTTP/2 requests, enabling downgrade request smuggling attacks. Affected versions span three major release branches: 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. This type of vulnerability can allow attackers to bypass security controls, poison caches, or hijack requests. Users are strongly recommended to upgrade to the patched versions 9.2.15 or 10.1.4. The issue has been assigned CVE-2026-58150 and is tracked by NVD.

Technical details

Mitigation steps:

Affected products:

Apache Traffic Server 8.0.0-8.1.9
Apache Traffic Server 9.0.0-9.2.14
Apache Traffic Server 10.0.0-10.1.3

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page