A critical vulnerability (CVE-2026-57834) has been identified in Apache Traffic Server, allowing request smuggling through improperly handled malformed chunked transfer-encoded messages. This flaw impacts versions 8.0.0-8.1.9, 9.0.0-9.2.14, and 10.0.0-10.1.3. Successful exploitation could enable attackers to bypass proxy restrictions, conduct cache poisoning, or perform cross-site request forgery attacks. The vulnerability carries a CVSS score of 10.0, indicating severe risk. All users of affected versions are strongly advised to upgrade to 9.2.15 or 10.1.4, which contain patches for this issue. Immediate remediation is critical to prevent potential exploitation via crafted HTTP requests. No workarounds are available for this high-severity flaw, which affects widely deployed proxy and caching infrastructure.
CRITICAL
CVSS 10.0
CVE-2026-57834
2026-08-16
Critical Request Smuggling Vulnerability in Apache Traffic Server (CVE-2026-57834)
Apache Traffic Server contains a critical request smuggling vulnerability (CVSS 10.0) affecting multiple versions. Attackers could exploit malformed chunked messages to bypass security controls. Users are advised to upgrade immediately.