A vulnerability described as critical has been identified in Apache Traffic Server up to 8.1.9/9.2.14/10.1.3. Affected is an unknown function of the component Multiplexer Plugin. Executing a manipulation can lead to buffer overflow.

This vulnerability is registered as CVE-2026-58187. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended.