CVE-2026-22068CWE-777

CVE-2026-22068

High · published July 29, 2026

CVSS v3.1
8.2
EPSS
0%
Percentile
34.2
In the wild
Unconfirmed
What it is

Regular Expression without Anchors vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 10.0.X through 10.1.3, from 9.0.X through 9.2.14.

Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.

The record
Technical detail
CVSS v3.1
8.2 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N
CVSS v4.0
Not supplied
EPSS
0.00410 · 34.2th percentile
Weakness
CWE-777 · Regular Expression without Anchors
Published
2026-07-29T12:16Z
Affected products (2)
ProductVersionsFixed in
apache/traffic_server≥ 9.0.0, < 9.2.159.2.15
apache/traffic_server≥ 10.0.0, < 10.1.410.1.4
References (1)
EPSS history
Timeline
  • 29 JUL 07:19Z
    Apache Traffic Server: Regex mappings match with malicious domain names
    cvelistv5