Apache Traffic Server leaks memory when handling HostDB SRV records. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
Apache Traffic Server contains a memory leak vulnerability (CWE-401) in its handling of HostDB SRV records that affects multiple versions across the 8.x, 9.x, and 10.x release lines. This vulnerability allows memory to accumulate without proper deallocation when the server processes Service (SRV) DNS records, potentially leading to denial of service through resource exhaustion. Organizations running affected versions—8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3—face increased risk if their Traffic Server instances handle DNS resolution or load balancing with SRV record lookups. The high CVSS score of 7.5 reflects the availability impact that sustained memory leaks can inflict on critical infrastructure.
While this specific CVE does not map directly to MITRE ATT&CK techniques in the vulnerability disclosure, Casky's AI-driven analysis with extended reasoning capabilities would identify the underlying resource exhaustion patterns that practitioners should monitor. Security teams using Casky would benefit from behavioral detection rules focused on process memory growth anomalies, abnormal DNS query patterns targeting SRV records, and performance degradation indicators in reverse proxy or load balancing infrastructure. By correlating these signals across your environment, practitioners can identify exploitation attempts even in variants or attack chains that leverage this vulnerability as a stepping stone. The absence of mapped skills in this spotlight underscores the importance of immediate patching to versions 9.2.15 or 10.1.4, combined with proactive memory and resource monitoring while upgrades are staged.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-58175. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation