CVE-2026-58182 HIGH

CVE-2026-58182: Apache Traffic Server: ts_lua plugin has initialization and resource-handling errors

Vendor Apache Software Foundation
Product Apache Traffic Server
Weakness CWE-400
Published July 29, 2026
Last update July 29, 2026

CVSS base score

8.6/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality Low
Integrity Low

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H

What the vulnerability does

01Description

The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Key dates

02Disclosure timeline

July 29, 2026 CVE published

Related vulnerabilities

04Related CVE