Bug 2454475 (CVE-2025-58136) - CVE-2025-58136 Apache Traffic Server: Apache Traffic Server: Denial of Service via POST request handling
Summary: CVE-2025-58136 Apache Traffic Server: Apache Traffic Server: Denial of Servic...
Keywords:
Status: NEW
Alias: CVE-2025-58136
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2454963 2454965
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-02 17:01 UTC by OSIDB Bzimport
Modified: 2026-04-03 22:18 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-04-02 17:01:53 UTC
A bug in POST request handling causes a crash under a certain condition.

This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12.

Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue.

A workaround for older versions is to set proxy.config.http.request_buffer_enabled to 0 (the default value is 0).


Note You need to log in before you can comment on or make changes to this bug.