CVE-2026-58156EPSS p30.6%

CVE-2026-58156CVE-2026-58156

apache / traffic_server

Description

Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.

Scoring

CVSS 4.9 ()
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
EPSS0.39% probability of exploitation · percentile 30.6% · 2026-10-05T12:00:23Z
Last modified2026-10-01
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.