


Perceptive Security
SOC/SIEM Consultancy

Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling.
This issue affects Apache Traffic Server: fro…
Published:
28 juli 2026 om 22:00:00
Alert date:
29 juli 2026 om 09:01:49
Source:
nvd.nist.gov
Network Infrastructure, Web Technologies
A vulnerability in Apache Traffic Server allows HTTP request smuggling via improper handling of Transfer-Encoding headers in HTTP/2 requests. The server fails to reject Transfer-Encoding in HTTP/2 requests, enabling downgrade request smuggling attacks. Affected versions span three major release branches: 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. This type of vulnerability can allow attackers to bypass security controls, poison caches, or hijack requests. Users are strongly recommended to upgrade to the patched versions 9.2.15 or 10.1.4. The issue has been assigned CVE-2026-58150 and is tracked by NVD.
Technical details
Mitigation steps:
Affected products:
Apache Traffic Server 8.0.0-8.1.9
Apache Traffic Server 9.0.0-9.2.14
Apache Traffic Server 10.0.0-10.1.3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-58150
https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
