


Perceptive Security
SOC/SIEM Consultancy

Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass.
This issue affects Apache Traffic Serve…
Published:
29 juli 2026 om 00:00:00
Alert date:
29 juli 2026 om 12:01:29
Source:
nvd.nist.gov
Network Infrastructure, Web Technologies
Apache Traffic Server contains a vulnerability where over-long HTTP header names are truncated, leading to header aliasing. This behavior can be exploited to perform request smuggling and bypass security policies. The issue affects multiple major versions: 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Request smuggling vulnerabilities can allow attackers to poison caches, hijack requests, or bypass access controls. The fix is available in versions 9.2.15 and 10.1.4. Users on affected versions are strongly recommended to upgrade immediately. No workarounds are described in the advisory.
Technical details
Mitigation steps:
Affected products:
Apache Traffic Server 8.0.0-8.1.9
Apache Traffic Server 9.0.0-9.2.14
Apache Traffic Server 10.0.0-10.1.3
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-58155
https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
