CVE-2025-58136Patch(apache / traffic_server)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache traffic_server systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A bug in POST request handling causes a crash under a certain condition. This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12. Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue. A workaround for older versions is to set proxy.config.http.request_buffer_enabled to 0 (the default value is 0).

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-670

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • traffic_server

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 7 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 4 mentions (2026-04-06); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
traffic_server

Deep dive

Activity timeline8 mentions / 4d
01234Mentions · 2026-04-03: 2Mentions · 2026-04-06: 4Mentions · 2026-04-13: 1Mentions · 2026-04-20: 1Patch / Workaround · 2026-04-03: 1Patch / Workaround · 2026-04-06: 4Technical Details · 2026-04-03: 2Technical Details · 2026-04-06: 4Technical Details · 2026-04-13: 104-0304-0604-1304-20
Signal classification3 categories
Patch
562.5%
Disclosure
225.0%
General
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-032
Disclosure1Patch1
2026-04-064
Patch4
2026-04-131
Disclosure1
2026-04-201
General1
Full discourse8 posts
  • Open Source Security mailing list@oss_security
    Disclosure

    Apache Traffic Server (ATS) is vulnerable to HTTP requests with body https://www.openwall.com/lists/oss-security/2026/04/02/6 CVE-2025-58136: A simple legitimate POST request causes a crash CVE-2025-65114: Malformed chunked message body allows request smuggling

    Post summary

    The text announces two CVEs for Apache Traffic Server, noting that a legitimate POST request crashes the server and a malformed chunked body enables request smuggling, but provides no PoC, exploit, patch, or active exploitation data.

    010711.1K
    4.6K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Apache Traffic Server fixes two CVSS 7.5 flaws (CVE-2025-58136 & CVE-2025-65114). Prevent DoS and request smuggling—update to 10.1.2 or 9.2.13 now! #ApacheTrafficServer #ATS #InfoSec #CyberSecurity #WebCache #RequestSmuggling #PatchAlert #SysAdmin https://securityonline.info/apache-traffic-server-vulnerabilities-dos-request-smuggling-patch/ https://t.co/RnycPZbl8T

    Post summary

    The tweet announces that Apache Traffic Server has two CVSS 7.5 flaws—CVE-2025-58136 and CVE-2025-65114 causing DoS and request smuggling—and urges users to patch to the latest release.

    01040626
    12.3K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos Apache ❗ CVE-2025-65114 ❗ CVE-2025-58136 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-apache-5/ https://t.co/0Cw71xkIId

    Post summary

    A brief notice listing two Apache CVEs with a link for more information; no details on exploitation, patches, or technical aspects are provided.

    00001355
    6.7K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Apache Traffic Server の脆弱性 CVE-2025-58136/65114 が FIX:DoS と HTTP スマグリングの可能性 https://iototsecnews.jp/2026/04/06/apache-traffic-server-vulnerabilities-let-attackers-trigger-dos-attack/ Apache Traffic Server (ATS) の問題は、HTTP リクエストのメッセージ・ボディを処理する際の、サーバの仕組みに起因するものです。具体的には、CVE-2025-58136 により、標準的な POST リクエストの処理不備からシステムが停止してしまう点や、 CVE-2025-65114 により、不正な形式のデータ処理をきっかけにリクエストの内容が誤認される点が挙げられます。これらは、通信の根幹に関わる部分の不具合であるため、普段利用する Web プロキシの動作に大きな影響が生じてしまいます。ご利用のチームは、ご注意ください。 #Apache #CVE202558136 #CVE202565114 #TrafficServer #Vulnerability

    Post summary

    The post announces the existence of two CVEs in Apache Traffic Server, providing some technical details about their effects but offers no PoC, exploit code, active exploitation evidence, or explicit patch information.

    01000170
    484 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Apache Traffic Server (CVE-2025-58136, CVE-2025-65114) and Dgraph Database (CVE-2026-34976) 📅 **Timeline:** Disclosure: 2026-04-06, Patch: 2026-04-06 🆔 **CVE-2026-34976** | 📊 CVSS: 10.0 (Critical 🔴) 🆔 **CVE-2025-58136** 🆔 **CVE-2025-65114** 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** Dgraph ≤25.3.0, Apache Traffic Server 9.0.0–9.2.12, Apache Traffic Server 10.0.0–10.1.1 🔧 **Fixed Versions:** Dgraph: pending, ATS 9.x → 9.1.13+, ATS 10.x → 10.1.2+ 🫨 **Attack Vectors:** - Dgraph: unauthenticated access to admin GraphQL (restoreTenant) allowing remote restore from attacker-controlled URL or file:// — SSRF and local file reads possible - ATS (CVE-2025-58136): crafted HTTP POST causing application crash (remote DoS) - ATS (CVE-2025-65114): malformed chunked message handling enabling HTTP request smuggling 📝 **Summary:** Dgraph’s flaw (CVE-2026-34976) allows unauthenticated admin restore, enabling DB overwrite, local file reads, and SSRF — full compromise of confidentiality/integrity/availability. Apache Traffic Server issues permit remote DoS and request smuggling that can poison caches or expose downstream data. 📈 **Impact Scope:** CVE-2026-34976 enables total loss of confidentiality, integrity, and availability (database overwrite, data exposure). ATS issues enable service disruption (DoS) and potential downstream data exposure/cache poisoning. 🛡️ **Recommended Actions:** - Apply ATS updates immediately: upgrade 9.x → 9.1.13+ or 10.x → 10.1.2+; apply Dgraph patch when released - If ATS cannot be patched now, set proxy.config.http.request_buffer_enabled = 0 as a temporary mitigation - Isolate and block public access to Dgraph admin endpoints (e.g., block port 8080) and treat backups as potentially suspect - Monitor logs and outbound requests for suspicious restore attempts, SSRF indicators, or unexpected egress 🪢 **Related Resources:** - https://github.com/dgraph-io/dgraph/security/advisories/GHSA-p5rh-vmhp-gvcw - https://lists.apache.org/thread/2s11roxlv1j8ph6q52rqo1klvl01n14q 🏷 **Tags:** #Cybersecurity #Dgraph #ApacheTrafficServer

    Post summary

    The post announces critical CVEs affecting Apache Traffic Server and Dgraph with detailed impact information and provides patch versions and mitigations.

    00000103
    273 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Apache Traffic Server Denial-of-Service and Request Smuggling Vulnerabilities 📅 **Timeline:** Disclosure: 2026-04-02, Patch: 2026-04-02 🆔 **CVE-2025-58136** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 12.25% 🆔 **CVE-2025-65114** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 8.20% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** 9.0.0 - 9.2.12, 10.0.0 - 10.1.1 🔧 **Fixed Versions:** 9.2.13, 10.1.2 🫨 **Attack Vectors:** - Network (remote unauthenticated) - Crafted POST requests causing crash (CVE-2025-58136) - Malformed chunked transfer encoding leading to HTTP request smuggling (CVE-2025-65114) - Proxy/backend interpretation mismatch enabling cache poisoning or bypass 📝 **Summary:** Two critical-path issues in Apache Traffic Server allow remote unauthenticated attackers to either crash ATS via crafted POSTs (availability) or perform HTTP request smuggling via malformed chunked bodies (integrity/confidentiality), enabling cache poisoning and bypasses. Patches 9.2.13 and 10.1.2 were released on 2026-04-02 — upgrade immediately and apply mitigations until patched. 📈 **Impact Scope:** Exposed ATS 9.x and 10.x instances risk outages, cache poisoning, request/response splitting, bypassed protections, and potential sensitive-data exposure to co-located users. 🛡️ **Recommended Actions:** - Upgrade ATS to 9.2.13 or 10.1.2 immediately (fixes both CVEs) - For CVE-2025-58136: as a temporary mitigation set proxy.config.http.request_buffer_enabled = 0 (default is 0) - Restrict ATS exposure to untrusted networks and apply ingress filtering - Deploy/adjust WAF/upstream validation to detect malformed chunked encoding and smuggling; audit logs and caches for anomalies; monitor vendor advisories 🪢 **Related Resources:** - https://cyberpress.org/apache-traffic-server-flaw/ - https://lists.apache.org/thread/2s11roxlv1j8ph6q52rqo1klvl01n14q 🏷 **Tags:** #Cybersecurity #ApacheTrafficServer #RequestSmuggling

    Post summary

    The notice alerts on two high‑severity vulnerabilities in Apache Traffic Server, provides patch releases, and recommends immediate upgrade and mitigations.

    00000115
    273 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Apache Traffic Server — two high-severity DoS / HTTP request smuggling vulnerabilities (CVE-2025-58136, CVE-2025-65114) 📅 **Timeline:** Disclosure: 2026-04-02, Patch: 2026-04-02 🆔 **CVE-2025-58136** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 12.25% 🆔 **CVE-2025-65114** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 8.20% 🛠️ **Exploit Maturity:** Not Available 📂 **Affected Versions:** ATS 9.0.0–9.2.12, ATS 10.0.0–10.1.1 🔧 **Fixed Versions:** 9.2.13, 10.1.2 🫨 **Attack Vectors:** - Network (remote, unauthenticated) - Crafted POST requests causing server crash (CVE-2025-58136) - Malformed chunked transfer-encoding leading to HTTP request smuggling (CVE-2025-65114) 📝 **Summary:** Two remote, high-severity flaws in Apache Traffic Server allow unauthenticated attackers to crash ATS via crafted POSTs (availability loss) or to perform HTTP request smuggling via malformed chunked encoding (enabling control bypass, cache poisoning, and request/response splitting). Both affect 9.x and 10.x branches and are fixed in 9.2.13 and 10.1.2. 📈 **Impact Scope:** Any exposed ATS instances running 9.0.0–9.2.12 or 10.0.0–10.1.1; impacts include service outage, proxy-control bypass, cache poisoning, and potential data exposure between proxied services. 🛡️ **Recommended Actions:** - Upgrade immediately to 9.2.13 or 10.1.2. - If unable to patch immediately, set proxy.config.http.request_buffer_enabled = 0 (partial mitigation for CVE-2025-58136). - Restrict/filter untrusted HTTP traffic at the network edge and monitor for exploit attempts. - Audit ATS and backend logs for crashes, malformed chunked requests, and cache anomalies; purge/validate caches after patching. 🪢 **Related Resources:** - https://lists.apache.org/thread/2s11roxlv1j8ph6q52rqo1klvl01n14q - https://nvd.nist.gov/vuln/detail/CVE-2025-58136 🏷 **Tags:** #Cybersecurity #ApacheTrafficServer #RequestSmuggling

    Post summary

    The alert discloses two high‑severity DoS and HTTP request smuggling flaws in Apache Traffic Server, provides detailed technical data, and urges immediate patching or mitigation steps.

    00000116
    273 followersView on X
  • Syed Aquib@syedaquib77
    Patch

    ⚠️ **Vulnerability Alert:** Apache Traffic Server — Two high-severity DoS/request-smuggling vulnerabilities (CVE-2025-58136, CVE-2025-65114) 📅 **Timeline:** Disclosure: 2026-04-02, Patch: 2026-04-02 🆔 **CVE-2025-58136** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 12.25% 🆔 **CVE-2025-65114** | 📊 CVSS: 7.5 (HIGH 🟠) | 📈 EPSS: 8.20% 🛠️ **Exploit Maturity:** Not Available (no public exploits reported) 📂 **Affected Versions:** Apache Traffic Server 9.0.0 - 9.2.12, Apache Traffic Server 10.0.0 - 10.1.1 🔧 **Fixed Versions:** 9.2.13, 10.1.2 🫨 **Attack Vectors:** - Network (remote, unauthenticated) — crafted POST request causing server crash (CVE-2025-58136) - Network (remote, unauthenticated) — malformed chunked transfer encoding enabling HTTP request smuggling (CVE-2025-65114) 📝 **Summary:** Two high-severity ATS flaws allow unauthenticated remote actors to crash servers via crafted POSTs (DoS) and to perform HTTP request smuggling via malformed chunked bodies, enabling cache poisoning and bypass of proxy controls. Both affect ATS 9.x (<=9.2.12) and 10.x (<=10.1.1) and are fixed in 9.2.13 and 10.1.2. 📈 **Impact Scope:** Availability impact (DoS/crash) and integrity/authorization impact (HTTP request smuggling: cache poisoning, bypassing proxy controls, request/response manipulation). Enterprise ATS deployments and reverse-proxy/caching infrastructure are at risk until patched. 🛡️ **Recommended Actions:** - Immediately upgrade ATS to 9.2.13 or 10.1.2 - If unable to patch immediately, set proxy.config.http.request_buffer_enabled = 0 to mitigate CVE-2025-58136 - Audit and restrict ATS exposure to untrusted networks; apply WAF/proxy rules to block malformed chunked requests - Monitor logs for crashes, unexpected 5xxs, request boundary anomalies and implement network-level filtering/rate-limiting 🪢 **Related Resources:** - https://cyberpress.org/apache-traffic-server-flaw/ - https://lists.apache.org/thread/2s11roxlv1j8ph6q52rqo1klvl01n14q 🏷 **Tags:** #Cybersecurity #ApacheTrafficServer #RequestSmuggling

    Post summary

    The post announces two high-severity DoS and request-smuggling vulnerabilities in Apache Traffic Server with clear CVSS scores and attack details, and provides immediate patching guidance and mitigation steps.

    00000112
    273 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetraffic_server---

Explore more