[Git][security-tracker-team/security-tracker][master] Add new trafficserver issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Jul 29 21:50:41 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a4551e43 by Salvatore Bonaccorso at 2026-07-29T22:50:20+02:00
Add new trafficserver issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -95,11 +95,14 @@ CVE-2026-65884 (Joomla Extension - balbooa.com - Privilege Escalation in Gridbox
CVE-2026-65883 (Joomla Extension - aimy-extensions.com - RCE via PHP object injection ...)
NOT-FOR-US: Joomla
CVE-2026-65325 (Apache Traffic Server reuses multiplexed HTTP/2 origin connections wit ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-65324 (Apache Traffic Server drops the per-stream buffer cap when dechunking ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-65100 (Apache Traffic Server updates the HTTP/2 HPACK dynamic table before co ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-64557 (In the Linux kernel, the following vulnerability has been resolved: B ...)
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/6fef032af0092ed5ccb767239a9ac1bc38c08a40 (7.2-rc3)
@@ -133,65 +136,95 @@ CVE-2026-59247 (Insufficient Verification of Data Authenticity vulnerability in
CVE-2026-59243 (The FAB auth manager's Azure AD OAuth login defaulted `verify_signatur ...)
NOT-FOR-US: Apache Airflow FAB provider
CVE-2026-58189 (Apache Traffic Server allows redirect-limit bypass when plugins reset ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58188 (Several Apache Traffic Server experimental plugins have memory-safety ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58187 (The Apache Traffic Server multiplexer plugin overruns its chunk-decode ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58186 (The Apache Traffic Server webp_transform plugin can decode unsafely an ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58185 (The Apache Traffic Server intercept plugin has a use-after-free. This ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58184 (The Apache Traffic Server header_rewrite plugin can crash or corrupt m ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58183 (The Apache Traffic Server prefetch plugin can crash when processing at ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58182 (The Apache Traffic Server ts_lua plugin mishandles initialization, tra ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58181 (The Apache Traffic Server uri_signing and url_sig plugins can exhaust ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58180 (The Apache Traffic Server txn_box plugin overflows the stack from atta ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58179 (The Apache Traffic Server regex_remap plugin overflows the stack and i ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58178 (The Apache Traffic Server ESI plugin can recurse without bound and fet ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58177 (The Apache Traffic Server Cripts framework has out-of-bounds writes, p ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58175 (Apache Traffic Server leaks memory when handling HostDB SRV records. ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58164 (Apache Traffic Server has use-after-free and time-of-check/time-of-use ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58163 (Apache Traffic Server mishandles on-disk cache fields and object lifet ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58162 (The Apache Traffic Server certifier plugin generates certificates base ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58161 (Apache Traffic Server can crash from null dereferences and dangling re ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58160 (Apache Traffic Server reads out of bounds while parsing DNS answers. ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58159 (Apache Traffic Server can bypass IP access controls on UDS listeners a ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58158 (Apache Traffic Server mishandles PROXY protocol input, truncating port ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58157 (Apache Traffic Server can reuse server sessions and tunnels improperly ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58156 (Apache Traffic Server mis-parses ports in URLs and userinfo, allowing ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58155 (Apache Traffic Server truncates over-long header names, allowing heade ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58154 (Apache Traffic Server can write out of bounds or overflow integers whi ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58153 (Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 client ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58152 (Apache Traffic Server mishandles integers while decoding HPACK/XPACK h ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58151 (Apache Traffic Server can be crashed or driven to resource exhaustion ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-58150 (Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requ ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-57834 (Apache Traffic Server allows request smuggling if chunked messages are ...)
- TODO: check
+ - trafficserver <unfixed>
+ NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-56390 (GNU Bison improperly handles grammar\u2011defined output paths. Gramma ...)
TODO: check
CVE-2026-56389 (GNU Bison allows for an execution of an arbitrary program during HTML ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a4551e43ed8cd8035ab38af5fa53b9a2caa96442
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a4551e43ed8cd8035ab38af5fa53b9a2caa96442
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/a931b4ce/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list