CVE-2026-58153

Summary

Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 clients without proper chunked framing when converting HTTP/2 to HTTP/1.

This issue affects Apache Traffic Server: from 10.0.0 through 10.1.3.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Affected Software

VendorProductVersion RangeStatus
Apache Software FoundationApache Traffic Server10.0.0 <= 10.1.3affected

Weaknesses

  • CWE-444: CWE-444 Inconsistent Interpretation of HTTP Requests

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References