A vulnerability identified as critical has been detected in Apache Traffic Server up to 8.1.9/9.2.14/10.1.3. The impacted element is an unknown function. This manipulation causes server-side request forgery.

This vulnerability is tracked as CVE-2026-58189. The attack is possible to be carried out remotely. No exploit exists.

You should upgrade the affected component.