A vulnerability marked as very critical has been reported in Apache Traffic Server up to 8.1.9/9.2.14/10.1.3. This impacts an unknown function of the component webp_transform plugin. Performing a manipulation results in improper input validation.

This vulnerability is cataloged as CVE-2026-58186. It is possible to initiate the attack remotely. There is no exploit available.

It is suggested to upgrade the affected component.