Live Exposure Defense: From CVE to Confirmed Exposure in 12 Hours – See more

New CVE Detected

CVE-2026-58189 – Server-Side Request Forgery (SSRF) Amplification / Denial of Service – Apache Traff

Be the first to know when new zero-days emerge:

Summary

CVE-2026-58189 is a Server-Side Request Forgery (SSRF) vulnerability in Apache Traffic Server caused by a redirect-limit bypass. When plugins reset the internal retry counter, the configured redirect limit can be circumvented, enabling SSRF amplification against back-end or third-party services. The issue is rated HIGH severity (CVSS v3.1 base score 7.5).

Technical details

  • Root cause: Apache Traffic Server allows a redirect-limit bypass when plugins reset the retry counter, defeating the control that is meant to cap how many redirects a single request will follow.
  • Trigger conditions: The retry counter being reset (in the plugin-driven redirect handling path) permits the redirect limit to be exceeded, allowing a request to be redirected repeatedly beyond the intended bound.
  • Attack vector: Network-based (AV:N), requiring no authentication, no privileges, and no user interaction.
  • Impact: SSRF amplification — an attacker can drive the proxy to issue an outsized volume of amplified redirect-driven requests, resulting in a high availability impact (denial of service). The CVSS vector indicates no confidentiality or integrity impact.

Affected software

  • Apache Traffic Server 8.0.0 through 8.1.9
  • Apache Traffic Server 9.0.0 through 9.2.14
  • Apache Traffic Server 10.0.0 through 10.1.3

Severity

  • CVSS v3.1 base score: 7.5 (HIGH)
  • Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Mitigation and recommended actions

  • Immediate: Upgrade to a fixed release. The 9.x branch is fixed in 9.2.15 and the 10.x branch is fixed in 10.1.4. Users on the 8.x branch should migrate to a supported, fixed release (9.2.15 or later).
  • If patching is not immediately possible: Review and restrict the use of plugins that reset the redirect/retry counter, and constrain outbound requests from Traffic Server using network-layer egress controls so the proxy cannot reach unintended internal or external destinations, limiting the SSRF amplification and denial-of-service exposure.

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

How IONIX’s External Exposure Management Platform Detects and Validates
Zero-Days to Shrink MTTR

1

Map your entire attack surface (continously)

IONIX uses multi-factor discovery methods, including DNS analysis, certificate mapping, metadata inspection, and more, to automatically map every internet-facing asset across your environment. This includes cloud instances, third-party platforms, shadow IT, and even forgotten infrastructure that traditional tools miss.

2

Monitor for new CVEs

Dozens of threat intel feeds using agentic technology are continuously analyzed to detect the appearance of proof-of-concept code, exploit kits, and indicators of active targeting. IONIX goes further by applying AI to proactively evaluate whether emerging vulnerabilities are likely to be exploited, even before PoCs go public.

3

Identify Potential External Exposures

Not all CVEs matter. IONIX filters vulnerabilities by asking attacker-centric questions: Can it be reached from the internet? Does it require authentication? Is it being exploited in the wild? This dramatically reduces noise and focuses teams on threats that can actually be weaponized.

4

Create Safe, Scalable Exploit Validations

IONIX transforms real-world PoCs into safe, non-intrusive test payloads that can be run in production environments without disruption. These simulations are precisely targeted to the systems that are vulnerable, ensuring rapid validation without unnecessary load.

5

Execute Exploit Validations

By combining context about software stack, versioning, exposure status, and reachability, IONIX ensures that only the right payloads are executed against the right assets, maximizing efficiency and minimizing risk.

6

Drive Fast and Actionable Remediation

Results are routed through integrations with ticketing, SOAR, and SIEM tools. Issues are written in plain language, bundled into remediation clusters, and prioritized based on asset criticality, exploitability, and blast radius. This shortens mean time to remediation (MTTR) and empowers teams to act with confidence.

Are you exposed?

Get a free report of your organization’s exposure to this CVE and threat

Subscribe to Threat Center RSS

Copy/paste the link below into your preferred RSS reader or follow these instructions to subscribe to Slack alerts.

Get Real-Time CVE Alerts to Your Email

Be the first to know when new zero-days emerge