CVE-2026-22068: CWE-777 Regular Expression without Anchors in Apache Software Foundation Apache Traffic Server
CVE-2026-22068 is a high-severity vulnerability in Apache Traffic Server involving a regular expression without anchors. This flaw affects versions from 9.0.x through 9.2.14 and 10.0.x through 10.1.3. The issue is resolved in versions 9.2.15 and 10.1.4. The vulnerability has a CVSS score of 8.2, indicating a network exploitable flaw with high confidentiality impact but low integrity and no availability impact.
AI Analysis
Technical Summary
This vulnerability (CVE-2026-22068) in Apache Traffic Server arises from the use of regular expressions without anchors, classified under CWE-777. Affected versions include 9.0.x through 9.2.14 and 10.0.x through 10.1.3. The lack of anchoring in regular expressions can lead to unintended matches, potentially allowing attackers to bypass intended input validation or filtering mechanisms. The CVSS 3.1 score is 8.2, reflecting a network attack vector with low attack complexity, no privileges required, no user interaction, and a high impact on confidentiality but limited impact on integrity and no impact on availability. Users are advised to upgrade to versions 9.2.15 or 10.1.4 where the issue is fixed.
Potential Impact
The vulnerability allows remote attackers to exploit improperly anchored regular expressions, potentially leading to unauthorized information disclosure (high confidentiality impact). The integrity impact is low, and there is no impact on availability. The flaw can be exploited over the network without authentication or user interaction.
Mitigation Recommendations
Users should upgrade Apache Traffic Server to version 9.2.15 or 10.1.4 to remediate this vulnerability. No other official remediation or temporary fixes are indicated. Patch status is confirmed by the vendor's version recommendations.
CVE-2026-22068: CWE-777 Regular Expression without Anchors in Apache Software Foundation Apache Traffic Server
Description
CVE-2026-22068 is a high-severity vulnerability in Apache Traffic Server involving a regular expression without anchors. This flaw affects versions from 9.0.x through 9.2.14 and 10.0.x through 10.1.3. The issue is resolved in versions 9.2.15 and 10.1.4. The vulnerability has a CVSS score of 8.2, indicating a network exploitable flaw with high confidentiality impact but low integrity and no availability impact.
CVSS v3.1
Score 8.2high
Affected software
Apache Software Foundation
Apache Traffic Server
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CVE-2026-22068) in Apache Traffic Server arises from the use of regular expressions without anchors, classified under CWE-777. Affected versions include 9.0.x through 9.2.14 and 10.0.x through 10.1.3. The lack of anchoring in regular expressions can lead to unintended matches, potentially allowing attackers to bypass intended input validation or filtering mechanisms. The CVSS 3.1 score is 8.2, reflecting a network attack vector with low attack complexity, no privileges required, no user interaction, and a high impact on confidentiality but limited impact on integrity and no impact on availability. Users are advised to upgrade to versions 9.2.15 or 10.1.4 where the issue is fixed.
Potential Impact
The vulnerability allows remote attackers to exploit improperly anchored regular expressions, potentially leading to unauthorized information disclosure (high confidentiality impact). The integrity impact is low, and there is no impact on availability. The flaw can be exploited over the network without authentication or user interaction.
Mitigation Recommendations
Users should upgrade Apache Traffic Server to version 9.2.15 or 10.1.4 to remediate this vulnerability. No other official remediation or temporary fixes are indicated. Patch status is confirmed by the vendor's version recommendations.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-01-06T00:14:54.783Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a69adc79c2644c7f825aa76
Added to database: 07/29/2026, 07:37:43 UTC
Last enriched: 08/05/2026, 15:08:53 UTC
Last updated: 09/10/2026, 20:00:31 UTC
Views: 93
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.