Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Apache Traffic Server fails to properly reject Transfer-Encoding headers in HTTP/2 requests, enabling request smuggling attacks that can downgrade security protections and bypass security controls. This critical vulnerability (CVSS 10.0) affects multiple versions across three major release branches (8.x, 9.x, and 10.x), potentially impacting numerous organizations using ATS as a reverse proxy or edge server. Request smuggling exploits the inconsistency between how front-end and back-end systems parse HTTP requests, allowing attackers to inject malicious requests, poison caches, or obtain unauthorized access to sensitive data. Any organization running affected versions should prioritize immediate patching to 9.2.15 or 10.1.4.
While this CVE currently has zero mapped MITRE ATT&CK techniques, Casky's platform would detect the exploitation patterns underlying this vulnerability through behavioral analysis of HTTP protocol anomalies. Practitioners using Casky's extended reasoning capabilities would observe suspicious patterns including: malformed HTTP/2 frame sequences containing Transfer-Encoding headers (a protocol violation), inconsistent content-length calculations across proxy layers, cache poisoning indicators, and request smuggling signatures that deviate from legitimate HTTP/2 specifications. Security teams would see findings highlighting protocol-level inconsistencies between client-facing and origin-server communications, enabling detection of both active exploitation attempts and potential downstream impacts on application security. This demonstrates how Casky's 754 mapped security skills can identify zero-day or unclassified attack patterns by analyzing protocol violations and request handling anomalies in real-time.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-58150. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation