trafficserver-10.1.4-1.fc44
- trafficserver-10.1.4-1.fc44
Update to upstream 10.1.4 Resolves: - CVE-2026-22068 - Unanchored regular-expression matching allows ACL and policy bypass - CVE-2026-33267 - Hop-by-hop and internal headers from untrusted peers are not stripped - CVE-2026-58150 - HTTP/2 requests with Transfer-Encoding are not rejected, allowing request smuggling - CVE-2026-58151 - Abusive HTTP/2 framing can exhaust resources and crash the server - CVE-2026-58154 - Memory-safety errors in MIME and header parsing - CVE-2026-58155 - Header-name length truncation enables header aliasing and request smuggling - CVE-2026-58157 - Improper server-session reuse can expose data across client connections - CVE-2026-58161 - Memory-safety errors in TLS and SNI handling can crash the server - CVE-2026-58177 - Memory-safety and path-traversal errors in the Cripts framework - CVE-2026-65324 - HTTP/2 and HTTP/3 dechunking removes per-stream buffer cap, allowing memory exhaustion - CVE-2026-24033 - Chunked extension quoted-string parsing allows request smuggling - CVE-2026-33930 - Buffer overflow via Host field that has a long string value - CVE-2026-41920 - SNI and Host comparison uses a one-sided length, allowing host-SNI policy bypass - CVE-2026-57834 - Malformed chunked message body allows request smuggling - CVE-2026-58152 - Integer-handling errors in HPACK/XPACK decoding corrupt memory - CVE-2026-58153 - HTTP/2 to HTTP/1 conversion forwards origin trailers to clients unsafely - CVE-2026-58156 - URL and port parsing errors allow access-control bypass - CVE-2026-58158 - PROXY protocol parsing has port truncation and a stack overflow - CVE-2026-58159 - Listener and ACL handling allow access-control bypass - CVE-2026-58160 - Out-of-bounds reads while parsing DNS responses - CVE-2026-58162 - Certifier plugin trusts client SNI when generating certificates - CVE-2026-58163 - Cache deserialization and lifetime errors can corrupt state or crash the server - CVE-2026-58164 - Remap configuration lifetime and TOCTOU errors cause use-after-free - CVE-2026-58175 - HostDB SRV handling leaks memory - CVE-2026-58178 - ESI plugin allows uncontrolled recursion and server-side request forgery - CVE-2026-58179 - regex_remap plugin overflows the stack from attacker input - CVE-2026-58180 - txn_box plugin overflows the stack from attacker input - CVE-2026-58181 - uri_signing and url_sig plugins can exhaust the stack or crash - CVE-2026-58182 - ts_lua plugin has initialization and resource-handling errors - CVE-2026-58183 - prefetch plugin can crash on attacker-influenced input - CVE-2026-58184 - header_rewrite plugin cookie handling can corrupt memory - CVE-2026-58185 - Use-after-free in the intercept plugin - CVE-2026-58186 - webp_transform plugin decodes unsafely and mislabels degraded responses - CVE-2026-58187 - Multiplexer plugin chunk decoder enables a denial of service - CVE-2026-58188 - Memory-safety and limit-bypass errors across experimental plugins - CVE-2026-58189 - Plugins resetting the redirect counter enable SSRF amplification - CVE-2026-65100 - HPACK encoder desynchronizes from the decoder after a failed header encode - CVE-2026-65325 - HTTP/2 multiplexed origin sessions are reused without certificate re-verification