Skip to content
Security updates: Attackers can crash Apache Traffic Server

Security updates: Attackers can crash Apache Traffic Server

Heise.De July 29, 2026

Apache Traffic Server can be attacked via over 38 software vulnerabilities. Among other things, attackers can trigger crashes via DoS attacks or bypass security mechanisms. So far, there are no indications of ongoing attacks from the software manufacturer. Admins should install the repaired versions promptly.

Apache Traffic Server is a caching proxy server and is primarily used in Content Delivery Networks (CDN). It is designed to process millions of requests per second.

If attackers successfully exploit the vulnerabilities, they can bypass geo-controls (CVE-2026-22068 “ high ”) and IP access controls (CVE-2026-58159 “ medium ”), among other things. In addition, DoS attacks are possible in various places. For example, sending prepared HTTP headers can lead to crashes (CVE-2026-58154 “ high ”).

In a post, the developers state that they have resolved the security issues in Apache Traffic Server 9.2.15 and 10.1.4 .

Recently, the Apache developers closed vulnerabilities in Apache Airflow with FAB authentication .

This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.