CVE-2026-22068
Regular Expression without Anchors vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 8.2
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:H/SI:N/SA:N
- EPSS probability
- 0.41%
- CWE
- CWE-777
- Published
- 2026-07-29
- Last modified
- 2026-07-29
Affected products
- Apache Software Foundation Apache Traffic Server
- Apache Software Foundation Apache Traffic Server
Weakness type
Related vulnerabilities
- CVE-2026-56021 — Webmin information disclosure via regex pattern
- CVE-2026-40110 — jupyter-server CORS origin validation bypass via unanchored regex in allow_origin_pat
- CVE-2026-39087 — ntfy before 2.22.0 allows SSRF because of an unanchored regular expression.