The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Apache Traffic Server ESI (Edge Side Includes) plugin contains an uncontrolled recursion vulnerability (CWE-674) that allows attackers to trigger infinite loops by crafting malicious ESI directives that fetch attacker-controlled URLs. This vulnerability affects multiple versions of Apache Traffic Server across three major release lines (8.0.0-8.1.9, 9.0.0-9.2.14, and 10.0.0-10.1.3), making it a widespread risk for organizations using these versions in their content delivery and edge computing infrastructure. With a CVSS score of 7.5, the vulnerability enables denial-of-service attacks that can exhaust server resources, crash the service, or facilitate further exploitation. Organizations running affected versions should prioritize upgrading to patched releases (9.2.15 or 10.1.4) immediately.
While this CVE doesn't map directly to MITRE ATT&CK techniques, Casky's skills powered by Claude AI would detect attack patterns associated with resource exhaustion and abuse of system functionality. Practitioners using Casky would identify suspicious indicators including: abnormal spike in recursive HTTP requests originating from the ESI plugin, excessive CPU and memory consumption tied to URL fetching operations, and repeated processing loops involving attacker-controlled domains in ESI directives. The platform's extended reasoning capabilities would correlate these findings with known denial-of-service patterns and application abuse techniques, enabling security teams to pinpoint the vulnerability exploitation even before traditional signature-based detection triggers. This proactive detection approach allows practitioners to respond to exploitation attempts before service degradation occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-58178. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation