PT-2026-29792 · Apache · Apache Traffic Server

Published

2026-04-02

·

Updated

2026-04-02

·

CVE-2025-58136

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
A bug in POST request handling causes a crash under a certain condition.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12.
Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue.
A workaround for older versions is to set proxy.config.http.request buffer enabled to 0 (the default value is 0).

Weakness Enumeration

Related Identifiers

CVE-2025-58136

Affected Products

Apache Traffic Server