← All Advisories

Apache Traffic Server Incorrect Control Flow Scores 7.5

Last refreshed2026-09-26

Status: UPDATED  |  Advisory ID: CVE-2025-58136

Key Details

CVECVE-2025-58136
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-09-24
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Proseattack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is none; integrity impact is none; availability impact is high.
Affected productsApache Traffic Server
Classified asCWE-670 (Always-Incorrect Control Flow Implementation)
Exploitation prediction (EPSS)0.67% probability of exploitation in the next 30 days (50% percentile) -- FIRST.org's EPSS model.

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
ApacheTraffic Server
SubsystemsGeneral OT
SectorsMultiple

What to Know

A bug in POST request handling causes a crash under a certain condition.

This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12.

Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue.

A workaround for older versions is to set proxy.config.http.request_buffer_enabled to 0 (the default value is 0).

What to Do

Monitor Apache's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-58136
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-58136
Vendor advisoryhttps://lists.apache.org/thread/2s11roxlv1j8ph6q52rqo1klvl01n14q