[Git][security-tracker-team/security-tracker][master] Add new trafficserver issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Jul 29 21:50:41 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a4551e43 by Salvatore Bonaccorso at 2026-07-29T22:50:20+02:00
Add new trafficserver issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -95,11 +95,14 @@ CVE-2026-65884 (Joomla Extension - balbooa.com - Privilege Escalation in Gridbox
 CVE-2026-65883 (Joomla Extension - aimy-extensions.com - RCE via PHP object injection  ...)
 	NOT-FOR-US: Joomla
 CVE-2026-65325 (Apache Traffic Server reuses multiplexed HTTP/2 origin connections wit ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-65324 (Apache Traffic Server drops the per-stream buffer cap when dechunking  ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-65100 (Apache Traffic Server updates the HTTP/2 HPACK dynamic table before co ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-64557 (In the Linux kernel, the following vulnerability has been resolved:  B ...)
 	- linux 7.1.5-1
 	NOTE: https://git.kernel.org/linus/6fef032af0092ed5ccb767239a9ac1bc38c08a40 (7.2-rc3)
@@ -133,65 +136,95 @@ CVE-2026-59247 (Insufficient Verification of Data Authenticity vulnerability in
 CVE-2026-59243 (The FAB auth manager's Azure AD OAuth login defaulted `verify_signatur ...)
 	NOT-FOR-US: Apache Airflow FAB provider
 CVE-2026-58189 (Apache Traffic Server allows redirect-limit bypass when plugins reset  ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58188 (Several Apache Traffic Server experimental plugins have memory-safety  ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58187 (The Apache Traffic Server multiplexer plugin overruns its chunk-decode ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58186 (The Apache Traffic Server webp_transform plugin can decode unsafely an ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58185 (The Apache Traffic Server intercept plugin has a use-after-free.  This ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58184 (The Apache Traffic Server header_rewrite plugin can crash or corrupt m ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58183 (The Apache Traffic Server prefetch plugin can crash when processing at ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58182 (The Apache Traffic Server ts_lua plugin mishandles initialization, tra ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58181 (The Apache Traffic Server uri_signing and url_sig plugins can exhaust  ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58180 (The Apache Traffic Server txn_box plugin overflows the stack from atta ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58179 (The Apache Traffic Server regex_remap plugin overflows the stack and i ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58178 (The Apache Traffic Server ESI plugin can recurse without bound and fet ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58177 (The Apache Traffic Server Cripts framework has out-of-bounds writes, p ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58175 (Apache Traffic Server leaks memory when handling HostDB SRV records.   ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58164 (Apache Traffic Server has use-after-free and time-of-check/time-of-use ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58163 (Apache Traffic Server mishandles on-disk cache fields and object lifet ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58162 (The Apache Traffic Server certifier plugin generates certificates base ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58161 (Apache Traffic Server can crash from null dereferences and dangling re ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58160 (Apache Traffic Server reads out of bounds while parsing DNS answers.   ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58159 (Apache Traffic Server can bypass IP access controls on UDS listeners a ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58158 (Apache Traffic Server mishandles PROXY protocol input, truncating port ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58157 (Apache Traffic Server can reuse server sessions and tunnels improperly ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58156 (Apache Traffic Server mis-parses ports in URLs and userinfo, allowing  ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58155 (Apache Traffic Server truncates over-long header names, allowing heade ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58154 (Apache Traffic Server can write out of bounds or overflow integers whi ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58153 (Apache Traffic Server forwards HTTP/2 origin trailers to HTTP/1 client ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58152 (Apache Traffic Server mishandles integers while decoding HPACK/XPACK h ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58151 (Apache Traffic Server can be crashed or driven to resource exhaustion  ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-58150 (Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requ ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-57834 (Apache Traffic Server allows request smuggling if chunked messages are ...)
-	TODO: check
+	- trafficserver <unfixed>
+	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-56390 (GNU Bison improperly handles grammar\u2011defined output paths. Gramma ...)
 	TODO: check
 CVE-2026-56389 (GNU Bison allows for an execution of an arbitrary program during HTML  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a4551e43ed8cd8035ab38af5fa53b9a2caa96442

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a4551e43ed8cd8035ab38af5fa53b9a2caa96442
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/a931b4ce/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list