Is wikipedia.org Safe? Security Score 84.9/100 | CyStack
wikipedia.org
Wikipedia
Wikipedia is a free online encyclopedia, created and edited by volunteers around the world and hosted by the Wikimedia Foundation.
Industry
Reference Materials / Dictionaries and Encyclopedias
Origin
United States
Global rank
#12
Rank in United States
#13
Updated at
B84.9/100
Security level
Good
Data confidence
High
Scope checked
100%
The higher the score, the more externally observable protections the system has recorded. This page does not certify that the website is reputable, legitimate, or completely free of vulnerabilities.
Is the website “wikipedia.org” safe?
As of July 21, 2026 at 13:39, wikipedia.org has a security score of 84.9/100 (grade B – “Good”). CyStack’s automated assessment recorded 10 issues to review after completing 100% of applicable checks. The website owner should address “Allowed browser content (CSP)” first, then review the remaining items in order of impact.
Does wikipedia.org show known scam, phishing, or malware signals?
At assessment time, CyStack did not find wikipedia.org or related infrastructure on any scam, phishing, or malware warning list after checking 5 online reputation sources. This result reflects external observations; it does not guarantee absolute safety or verify the organization’s legal status or reputation.
Compare the security level of each assessed category at a glance.
Network attack surface95.5/100 · Good100% of this category was checked
Web security50/100 · Review100% of this category was checked
Frequently asked questions
What affects the security of wikipedia.org?
A valid SSL certificate still does not prove that wikipedia.org is safe, legitimate, or free of scam signals. For a more complete assessment, this report also checks phishing and malware, exposed email records, IPs and open ports, subdomains, technologies, and CVEs that may apply to observed versions.
Does wikipedia.org use HTTPS, and is its SSL certificate valid?
wikipedia.org used a valid SSL certificate at assessment time, valid until September 5, 2026. This status may change when the certificate expires or the server configuration changes.
Have @wikipedia.org email addresses appeared in exposed data or information-stealer (infostealer) logs?
Data sources
Data compiled from CyStack cybersecurity monitoring systems
CyStack compiles scan results from its internal cybersecurity monitoring systems, including CyStack VulnScan and CyStack Threat Intelligence, together with publicly available Internet data. The assessment only observes and analyzes information already available; it does not attempt unauthorized access, test passwords, send exploit code, or change or disrupt the assessed system.
There are 3 issues to prioritize because they have the greatest impact on the security of wikipedia.org.
Allowed browser content (CSP)This check found a security issue.High
Check result
This check found a security issue.
Why it matters
Content Security Policy (CSP) limits where scripts, styles, frames, and other browser content may come from. A strong policy reduces the impact if an attacker manages to inject content into a page.
What to do
Define only the sources the application needs, test the policy before activating it, and avoid broad wildcard (*) rules, unsafe-inline, and unsafe-eval where possible.
Potential CVEs for observed versionsFound 37 potentially applicable CVE candidate(s), including 29 high or critical candidate(s).High
Check result
Found 37 potentially applicable CVE candidate(s), including 29 high or critical candidate(s).
Why it matters
The detected product and version were compared with vulnerability records from the National Vulnerability Database (NVD). A match is a lead, not confirmation: the installed software may include vendor fixes or may differ from the version visible on the Internet.
Protection from deceptive framing (clickjacking)This check found a security issue.Medium
Check result
This check found a security issue.
Why it matters
Another website can place this page inside a hidden or misleading frame and trick a user into clicking an unintended action. Frame restrictions tell browsers which sites, if any, may embed the page.
What to do
Set frame-ancestors in CSP to the required trusted sites, and keep X-Frame-Options for older browsers when appropriate.
Transport encryption
100/100 · Good
100% of this category was checked
Threat reputation100/100 · Good100% of this category was checked
Vulnerability and technology risk78.6/100 · Fair100% of this category was checked
Email authentication94.6/100 · Good100% of this category was checked
Data exposure50/100 · Review100% of this category was checked
Domain and DNS hygiene97.2/100 · Good100% of this category was checked
Issues to review
The complete list of issues to review, including the three priorities highlighted in the summary.
Content Security Policy (CSP) limits where scripts, styles, frames, and other browser content may come from. A strong policy reduces the impact if an attacker manages to inject content into a page.
What to do
Define only the sources the application needs, test the policy before activating it, and avoid broad wildcard (*) rules, unsafe-inline, and unsafe-eval where possible.
Potential CVEs for observed versionsSoftware vulnerabilitiesNeeds review
Check result
Found 37 potentially applicable CVE candidate(s), including 29 high or critical candidate(s).
Why it matters
The detected product and version were compared with vulnerability records from the National Vulnerability Database (NVD). A match is a lead, not confirmation: the installed software may include vendor fixes or may differ from the version visible on the Internet.
Protection from deceptive framing (clickjacking)Website protectionFailed
Check result
This check found a security issue.
Why it matters
Another website can place this page inside a hidden or misleading frame and trick a user into clicking an unintended action. Frame restrictions tell browsers which sites, if any, may embed the page.
Without the nosniff setting, a browser may guess a file's type and treat harmless-looking content as executable code. This can turn an incorrect Content-Type into a security issue.
What to do
Send X-Content-Type-Options: nosniff on every response and return an accurate Content-Type.
CyStack confirmed at least 774 active DNS subdomains. 2 names may expose sensitive services; discovery was partial, so more may exist.
Why it matters
Names containing admin, development, staging, VPN, database, or monitoring terms may point attackers toward valuable systems. A name alone does not prove exposure, but it identifies a surface that should be reviewed.
SPF protection levelEmail protectionNeeds review
Check result
The terminal SPF policy is ~all.
Why it matters
The final SPF rule tells receiving services how confidently they should reject unlisted senders. A permissive result allows more spoofed mail to appear legitimate than a hard fail (-all).
What to do
Confirm that every legitimate sender is included, then end the SPF record with -all.
3 email exposure records have an identity domain exactly matching this target and are associated with approximately 2 infected devices. These are intelligence observations; they do not prove that the email accounts are still active or that the devices belong to the organization.
Why it matters
Infostealer intelligence may contain credentials associated with the domain, but it does not prove that an account is current, valid, or still exposed.
Permissions-Policy controls whether this page and embedded content may use features such as the camera, microphone, and location. Leaving unused features available creates unnecessary access paths.
When a visitor follows a link, the browser may send the previous page's URL to the destination. Paths and query values in that URL can reveal sensitive context to another website.
What to do
Use strict-origin-when-cross-origin or a stricter Referrer-Policy, and avoid placing secrets in URLs.
DNS response protection (DNSSEC)Domain and DNSNeeds review
Check result
No DNSSEC DS delegation was found.
Why it matters
DNSSEC adds digital signatures so resolvers can detect forged DNS answers. This quick check confirms the parent domain has a DS record, but it does not validate the complete signature chain.
What to do
Sign the DNS zone, publish the matching DS record through the registrar, and monitor the signature chain after key changes.
Other evaluated controls (42)
Certificate matches the websiteHTTPS and encryption
Check result
The certificate matches the requested target.
Why it matters
The certificate must list the exact hostname visitors requested in its Subject Alternative Names (SAN). A mismatch produces browser warnings because the certificate may belong to a different service.
What to do
Issue and deploy a certificate whose SAN list includes every public hostname served by this website address.
Browsers trust a website only when its certificate can be traced to a recognized certificate provider. An untrusted certificate causes warnings and prevents visitors from reliably confirming the website's identity.
What to do
Install a certificate from a provider trusted by common browsers and configure the server to send every required intermediate certificate.
Data recorded by the system
Certificate issuer:
CN=YE1,O=Let's Encrypt,C=US
Secure website connection (HTTPS)HTTPS and encryption
Check result
A TLS handshake succeeded on port 443.
Why it matters
HTTPS encrypts data between visitors and the website and helps prove they reached the intended service. Without it, network observers may read or alter traffic and browsers may show a security warning.
What to do
Provide the entire website over HTTPS using a certificate trusted by common browsers.
No matched candidate was listed as a known-exploited vulnerability.
Why it matters
A possible CVE match also appears in the CISA Known Exploited Vulnerabilities (KEV) catalog, which means attackers have used that vulnerability in real incidents. The match is urgent to investigate, but the installed software still needs to be confirmed as affected.
What to do
Verify the installed product immediately and follow the CISA and vendor instructions for mitigation, patching, or upgrading if it is affected.
Public DNS connects the domain to its Internet addresses. Missing or incorrect records can make the service unreachable or send traffic to the wrong system.
What to do
Make sure the domain resolves only to its intended public IP addresses, and remove private, reserved, or outdated records.
Data recorded by the system
IP addresses:
103.102.166.224, 2001:df2:e500:ed1a::1
Password form transport securityWebsite protectionNot applicable
Check result
This check does not apply to the target.
Why it matters
If either a password page or the address receiving its form uses HTTP, someone observing the network may read or change the submitted password.
What to do
Serve every page containing a password field over HTTPS and submit each password form directly to an HTTPS address.
Data recorded by the system
Password forms:
0
Public management service exposurePublic infrastructure
Check result
No public management service was found on the scanned TCP port set.
Why it matters
Remote administration services such as RDP, VNC, Docker, Kubernetes, and management consoles are high-value targets. Public exposure allows anyone on the Internet to attempt passwords or exploit an unpatched service.
What to do
Remove direct Internet access and require a VPN, a hardened access gateway, or trusted source networks; also use MFA where supported.
Data recorded by the system
Complete:
Yes
Fingerprint Complete:
No
Fingerprint Error Code:
Fingerprint Incomplete
Fingerprint Identified:
2
Database or cache exposed to the InternetPublic infrastructure
Check result
No public datastore service was found on the scanned TCP port set.
Why it matters
Databases and caches often contain sensitive information and are normally used only by internal applications. Direct Internet access makes password attacks and configuration mistakes much more likely to become a data breach.
What to do
Listen only on private interfaces, allow connections only from required application systems, and require strong authentication and encryption.
Data recorded by the system
Complete:
Yes
Fingerprint Complete:
No
Fingerprint Error Code:
Fingerprint Incomplete
Fingerprint Identified:
2
File-sharing service exposed to the InternetPublic infrastructure
Check result
No public file-sharing service was found on the scanned TCP port set.
Why it matters
Services such as SMB, NFS, and rsync can reveal or modify shared files and have a history of serious vulnerabilities. They rarely need to accept connections directly from the public Internet.
What to do
Limit file-sharing services to private networks or a tightly controlled VPN, and allow only the users and systems that require access.
Data recorded by the system
Complete:
Yes
Fingerprint Complete:
No
Fingerprint Error Code:
Fingerprint Incomplete
Fingerprint Identified:
2
Unencrypted legacy servicePublic infrastructure
Check result
No public legacy cleartext service was found on the scanned TCP port set.
Why it matters
Older services such as Telnet, FTP, and unencrypted mail or directory protocols can send passwords and data in readable form. Anyone able to observe the network path may capture them.
What to do
Disable the legacy service or replace it with an encrypted alternative such as SSH, SFTP, HTTPS, or the secure version of the mail protocol.
Data recorded by the system
Complete:
Yes
Fingerprint Complete:
No
Fingerprint Error Code:
Fingerprint Incomplete
Fingerprint Identified:
2
Cookies sent only over HTTPS (Secure)Website protection
Check result
No issue was found by this check.
Why it matters
The Secure attribute prevents a browser from sending a cookie over unencrypted HTTP. Without it, session or authentication data may be exposed to someone observing the network.
What to do
Set Secure on every session, authentication, and other sensitive cookie served by the HTTPS application.
Data recorded by the system
Cookies using HttpOnly:
3
Cookies missing SameSite:
0
Cookies using Secure:
5
Total:
5
Cross-site access rules (CORS)Website protection
Check result
No issue was found by this check.
Why it matters
Cross-Origin Resource Sharing (CORS) decides which websites may read responses from this service in a visitor's browser. Rules that trust arbitrary origins, especially with login cookies, can expose private data to another website.
What to do
Allow only explicitly trusted websites, compare the Origin value with an exact approved list, and never allow login credentials with the wildcard origin (*).
Data recorded by the system
Arbitrary origin accepted:
No
Credentials allowed:
No
Allows all origins:
No
Certificate expiry and validityHTTPS and encryption
Check result
The certificate is valid from 2026-06-06T20:06:44Z to 2026-09-04T20:06:43Z.
Why it matters
A certificate works only between its start and expiry dates. An expired, not-yet-valid, or soon-to-expire certificate can trigger browser warnings and interrupt access to the website or API.
What to do
Use automatic renewal, monitor renewal failures, and alert the responsible team well before expiry.
Data recorded by the system
Days remaining:
45.6
Expires at:
Valid from:
Certificate key and signature strengthHTTPS and encryption
Check result
The certificate uses ECDSA-SHA384 with a 256-bit public key.
Why it matters
The certificate's public key and signature algorithm protect it from forgery. Keys that are too short or signatures based on obsolete algorithms provide less protection against modern attacks.
What to do
Use RSA with at least 2048 bits or a modern elliptic-curve key, and use SHA-256 or a stronger signature algorithm.
Data recorded by the system
Public-key algorithm:
ECDSA
Public-key size:
256
Signature algorithm:
ECDSA-SHA384
Supported TLS versionsHTTPS and encryption
Check result
Accepted versions: TLS 1.2, TLS 1.3.
Why it matters
TLS 1.0 and TLS 1.1 use outdated security designs and are no longer accepted by modern standards. Leaving them enabled allows older, weaker connection methods.
What to do
Disable TLS 1.0 and TLS 1.1, support TLS 1.2 securely, and enable TLS 1.3 where possible.
No independent abuse-list consensus was found across 5 definitive providers.
Why it matters
Security and email providers maintain DNS-based blacklists of IP addresses associated with spam, malware, or compromised systems. Several current, independent listings are a strong reason to investigate, although a shared IP can sometimes affect unrelated customers.
What to do
Verify each listing against the affected IP, investigate mail and host activity, fix the underlying cause, and then follow the provider's removal process.
Data recorded by the system
Blocklists with no match:
5
Confirmed blocklist matches:
No
Blocklists checked conclusively:
5
Blocklists unavailable:
1
DMARC blocking policyEmail protection
Check result
The effective DMARC policy is reject.
Why it matters
A policy of quarantine or reject tells receiving services to move suspicious mail to spam or refuse it. A monitoring-only policy (p=none) records the problem but does not ask receivers to stop spoofed mail.
What to do
After every legitimate sender passes DMARC, move gradually to quarantine and then reject, covering 100% of messages.
Data recorded by the system
Declared policy:
reject
Effective policy:
reject
DMARC policy setting:
p
Test mode:
No
References
Email spoofing protection (DMARC)Email protection
Check result
A DMARC policy was found.
Why it matters
DMARC lets the domain owner tell receiving services what to do when the visible From address is not verified by SPF or DKIM. Without DMARC, attackers have more opportunity to impersonate the domain in phishing email.
What to do
Publish a DMARC record at _dmarc, begin by collecting reports, and confirm that legitimate senders pass before applying a blocking policy.
The core DMARC policy tags passed structural validation.
Why it matters
Receiving services may ignore a DMARC record that contains duplicate fields, invalid values, or is published at the wrong DNS name. An ignored record provides no reliable protection from domain impersonation.
What to do
Publish one valid DMARC record at _dmarc and correct duplicate fields, unsupported values, and invalid report addresses.
An expired domain stops directing users to the organization's services and may eventually become available to someone else. A domain close to expiry leaves little time to recover from payment or account problems.
What to do
Renew well before the expiry date, enable automatic renewal, and protect the payment method and registrar account.
Data recorded by the system
Days remaining:
175.7
Registration expires at:
Domain registration statusDomain and DNS
Check result
RDAP returned 3 status value(s); 0 require attention.
Why it matters
Registrar or registry restrictions such as hold, redemption, or pending deletion can disable the domain. If they are not resolved, the organization may lose control of its website and email identity.
What to do
Resolve registration restrictions promptly, protect the registrar account with MFA, and keep ownership and contact information current.
Data recorded by the system
Registration statuses:
client delete prohibited, client transfer prohibited, client update prohibited
Session cookies protected from scripts (HttpOnly)Website protectionNot applicable
Check result
No cookie name matched the bounded session-cookie heuristic.
Why it matters
HttpOnly prevents browser scripts from directly reading a cookie. It does not fix script injection, but it makes theft of session and authentication cookies more difficult.
What to do
Set HttpOnly on session and authentication cookies unless the application has a documented need to read them in browser code.
SameSite limits when a browser includes cookies in requests started by another website. This helps prevent another site from silently making an authenticated request on a user's behalf.
What to do
Use SameSite=Lax or Strict by default. Use SameSite=None only for a required cross-site flow and always combine it with Secure.
Data recorded by the system
Cookies missing SameSite:
0
SameSite=None cookies missing Secure:
0
Total:
5
Insecure content on an HTTPS pageWebsite protection
Check result
No issue was found by this check.
Why it matters
An HTTPS page can still load scripts, frames, styles, or forms over unencrypted HTTP. An attacker on the network may alter that content and compromise the otherwise secure page.
What to do
Load every script, frame, stylesheet, and form destination over HTTPS, and remove or replace resources that do not support it.
Data recorded by the system
Insecure page resources:
0
Complete certificate chainHTTPS and encryption
Check result
The server presented 4 certificate(s).
Why it matters
The server must provide the intermediate certificates that connect its website certificate to a trusted provider. If any are missing, some browsers, mobile devices, or API clients may reject the connection.
What to do
Configure the server to send the website certificate followed by every required intermediate certificate, but not the root certificate.
Data recorded by the system
Certificates in the chain:
4
HSTS availabilityHTTPS and encryption
Check result
The HTTPS response enables HSTS.
Why it matters
HTTP Strict Transport Security (HSTS) tells a browser to use HTTPS automatically on future visits. This reduces the chance that a visitor is downgraded to an unencrypted connection.
What to do
After confirming that every required page works over HTTPS, send the Strict-Transport-Security header on all HTTPS responses.
Data recorded by the system
Includes subdomains:
Yes
Validity period in seconds:
106,384,710
Requests browser preloading:
Yes
Configured:
Yes
Valid:
Automatic redirect to HTTPSHTTPS and encryption
Check result
The HTTP root redirects to HTTPS within the target domain.
Why it matters
Visitors may enter an address beginning with HTTP or follow an old link. Redirecting them immediately to HTTPS prevents the rest of the visit from continuing over an unencrypted connection.
What to do
Redirect every HTTP URL directly to its corresponding HTTPS URL without passing through another HTTP address.
Data recorded by the system
Final connection:
https
Website reachable:
Yes
Redirects followed:
2
Public directory listingSoftware vulnerabilities
Check result
The root page did not match a common automatic directory-index pattern.
Why it matters
When a web server automatically lists a directory, visitors may discover files that were never linked publicly, including backups, logs, or deployment artifacts.
What to do
Disable automatic directory indexes unless public file browsing is an intentional feature, and remove sensitive files from web-accessible folders.
Data recorded by the system
Directory listing pattern found:
No
Homepage only:
Yes
Authorized email senders (SPF)Email protection
Check result
An SPF record was found.
Why it matters
Sender Policy Framework (SPF) lists the systems allowed to send email for the domain. Without it, receiving services have less evidence to distinguish legitimate mail from spoofed mail.
What to do
Publish one SPF TXT record that includes every legitimate email service and no unauthorized sender.
More than one SPF record, invalid terms, or too many DNS lookups can make SPF return a permanent error. Receiving services may then be unable to verify authorized senders.
What to do
Keep one valid SPF record, remove invalid terms, and remain within the SPF limit of ten DNS-based lookups.
MX records direct incoming email to the correct mail servers. Broken records can stop delivery, while a Null MX clearly tells senders that the domain does not receive email.
What to do
Correct unreachable or outdated MX hosts, or publish a Null MX if the domain is not intended to receive email.
Data recorded by the system
Does not receive email:
No
Unnecessary public servicesPublic infrastructure
Check result
No public unexpected service was found on the scanned TCP port set.
Why it matters
Every open service can be discovered and attacked and must be configured, monitored, and patched. Services without a clear public purpose add risk without providing business value.
What to do
Confirm the owner and purpose of every open port, then stop or firewall any service that is not intentionally public.
Data recorded by the system
Complete:
Yes
Fingerprint Complete:
No
Fingerprint Error Code:
Fingerprint Incomplete
Fingerprint Identified:
2
HSTS protection periodHTTPS and encryption
Check result
The HSTS max-age is at least 180 days.
Why it matters
The max-age value controls how long browsers remember to use HTTPS. A very short period provides limited protection, while includeSubDomains also covers every subdomain and can break one that does not support HTTPS.
What to do
Use a long max-age, and add includeSubDomains only after confirming that every active subdomain works correctly over HTTPS.
Data recorded by the system
Includes subdomains:
Yes
Validity period in seconds:
106,384,710
Requests browser preloading:
Yes
Configured:
Yes
Exposed software versionSoftware vulnerabilities
Check result
No issue was found by this check.
Why it matters
Exact web server or framework versions help attackers quickly look for known weaknesses that may apply. Hiding a version is not a substitute for patching, but unnecessary disclosure gives away useful targeting information.
What to do
Remove unnecessary version details from Server, X-Powered-By, error pages, and application metadata, and keep the software patched.
DMARC monitoring reportsEmail protection
Check result
Aggregate reporting is configured.
Why it matters
DMARC aggregate reports show which systems send email using the domain and which messages fail verification. They help find both impersonation attempts and legitimate services that need correction.
What to do
Add an aggregate report address (rua) that is protected and monitored, or use a trusted DMARC reporting service.
A domain should clearly state whether it receives email. Without valid MX records or a Null MX, senders may try an unintended server and delivery behavior becomes unpredictable.
What to do
Publish valid MX records for the intended mail servers, or a Null MX if the domain never accepts email.
Data recorded by the system
Does not receive email:
No
Allowed certificate issuers (CAA)Domain and DNS
Check result
Found 3 applicable CAA record(s).
Why it matters
Certificate Authority Authorization (CAA) records state which certificate providers may issue certificates for the domain. This reduces the chance of an unintended provider issuing one.
What to do
Publish CAA records that allow only the certificate providers your organization actually uses.
Authoritative name servers tell visitors where the domain is hosted. Depending on only one server creates a single point of failure for the website and email.
What to do
Use at least two authoritative name servers, preferably on independent and resilient infrastructure.
5 providers were definitive and 1 were inconclusive.
Why it matters
This shows how many independent blacklist services returned a clear result. A service that was unavailable was not checked successfully and must not be treated as a clean result.
Data recorded by the system
Blocklists with no match:
5
Confirmed blocklist matches:
No
Blocklists checked conclusively:
5
Blocklists unavailable:
1
Technologies visible from the InternetSoftware vulnerabilitiesInformation
Check result
Public signals from the website and its open services revealed 2 technology item(s).
Why it matters
Response headers, page content, and other public clues suggest which technologies the service uses. These observations help explain the attack surface, but they can be incomplete or mistaken and do not by themselves confirm a vulnerability.
Data recorded by the system
Technologies found:
2
Detection method:
Website and exposed-service analysis
Root Response Count:
2
Service Inventory Complete:
No
Observed WAF, CDN, or edge serviceSoftware vulnerabilitiesInformation
Check result
No WAF, CDN, or edge product matched the passive root-response signals; this does not prove that protection is absent.
Why it matters
Public response details suggest that a Web Application Firewall (WAF), CDN, or other edge service is present. This quick scan identified the provider but did not test whether attack blocking is configured or working correctly.
Observed 1 versioned product(s); 1 had exact CPE mappings and 1 completed lookup(s).
Why it matters
This shows how many detected products had reliable version information and an exact CPE identity, allowing them to be checked against CVE applicability data. A product that could not be checked must not be treated as free of known vulnerabilities.
Potentially exposed domain email addressesChecks infostealer data only for email addresses whose domain exactly matches this target. A record is not counted merely because someone visited or signed in to this website.3 Matching email exposure records
3Matching email exposure records
2Related infected devices (estimated)
These matching email records were observed previously, but they may already have been addressed or may no longer be valid. The device count estimates infected devices associated with these email records; it is not the number of devices owned by the organization.
Leak evidenceMost recent observation:
Email addressRelated infected deviceInfection evidenceRecorded time
Email addressS****@wikipedia.orgRelated infected deviceNo safely shareable device details are available for this record.IOC reference: IOC-5DE03C46C8Infection evidence
Discovered subdomains (774+)Subdomains discovered by CyStack, with sensitive-looking names shown first. Availability is verified during this assessment; individual subdomains have not been separately security-tested.Partial
Results were bounded and may be truncated.
test.m.wikipedia.orgSensitive-lookingDevelopment / testingMobile service
test.wikipedia.orgSensitive-looking
Public web contextThe website title, description, industry and popularity.
Page title
Wikipedia
Website category
Reference Materials / Dictionaries and Encyclopedias
Description
Wikipedia is a free online encyclopedia, created and edited by volunteers around the world and hosted by the Wikimedia Foundation.
Global rank
#12
Rank in United States
#13
Rank in industry
#1
This is a quick, point-in-time check from outside the organization. It can surface visible risks, but it does not replace penetration testing or an authenticated assessment.
There are currently 3 exposed email records matching the wikipedia.org domain. These records may be old or already resolved. The website owner should verify them before resetting passwords or locking related accounts.
Which public IPs, services, and ports does wikipedia.org expose?
The assessment observed 2 public IPs and 2 open ports for wikipedia.org; the infrastructure appears to be operated by Wikimedia Foundation, Inc.. An open port is not automatically a vulnerability, but every public service should be updated and appropriately restricted.
How many subdomains of wikipedia.org have been discovered?
The assessment observed 774+ public subdomains of wikipedia.org. This list can reveal additional entry points such as APIs, administration systems, or test environments, but it does not mean that every subdomain is risky.
Confirm the exact installed package and read the vendor advisory. If that installation is affected, apply the vendor patch or upgrade to a fixed version.
Confirm the exact installed package and read the vendor advisory. If that installation is affected, apply the vendor patch or upgrade to a fixed version.
Review the masked evidence and observation time, validate affected accounts and devices, then reset active credentials and sessions, enforce MFA, and remove malware where confirmed.
Data recorded by the system
Distinct affected devices observed:
2
Estimated infostealer-infected devices:
2
Evidence Mask Policy:
Length Preserving V2
Evidence samples shown:
3
Evidence sample limit:
10
Evidence samples available:
Yes
More evidence samples exist:
No
Matching exposed email records:
3
How exposed email records are matched:
Only email addresses whose domain exactly matches this website
Most recently observed:
Allow each sensitive browser feature only for the pages and trusted origins that require it, and disable the rest.
Apache Traffic Server is an open-source caching and proxying server that serves as an HTTP/1.1 and HTTP/2 reverse proxy with caching capabilities, load balancing, request routing, SSL termination, and support for advanced HTTP features.
Client Delete Prohibited, Client Transfer Prohibited, Client Update Prohibited
StealC
Recorded time
Email addressN********@wikipedia.orgRelated infected deviceNo safely shareable device details are available for this record.IOC reference: IOC-5DE03C46C8Infection evidenceStealCRecorded time
Email addressa******************@wikipedia.orgRelated infected deviceA************* (Windows 11 Pro (10.0.26100) x64)PakistanIOC reference: IOC-ED81F9FD3CInfection evidenceLummaObserved application: Edge Default (136.0.3240.76)Recorded time
Development / testing
15.wikipedia.org
aa.m.wikipedia.orgMobile service
aa.wikipedia.org
ab.m.wikipedia.orgMobile service
ab.wikipedia.org
abstract.wikipedia.org
ace.m.wikipedia.orgMobile service
ace.wikipedia.org
ady.m.wikipedia.orgMobile service
ady.wikipedia.org
Show 488 more
af.m.wikipedia.orgMobile service
af.wikipedia.org
ak.m.wikipedia.orgMobile service
ak.wikipedia.org
als.m.wikipedia.orgMobile service
als.wikipedia.org
alt.m.wikipedia.orgMobile service
alt.wikipedia.org
am.m.wikipedia.orgMobile service
am.wikipedia.org
ami.m.wikipedia.orgMobile service
ami.wikipedia.org
an.m.wikipedia.orgMobile service
an.wikipedia.org
ang.m.wikipedia.orgMobile service
ang.wikipedia.org
ann.m.wikipedia.orgMobile service
ann.wikipedia.org
anp.m.wikipedia.orgMobile service
anp.wikipedia.org
ar.m.wikipedia.orgMobile service
ar.wikipedia.org
arbcom-cs.m.wikipedia.orgMobile service
arbcom-cs.wikipedia.org
arbcom-de.m.wikipedia.orgMobile service
arbcom-de.wikipedia.org
arbcom-en.m.wikipedia.orgMobile service
arbcom-en.wikipedia.org
arbcom-fi.m.wikipedia.orgMobile service
arbcom-fi.wikipedia.org
arbcom-nl.m.wikipedia.orgMobile service
arbcom-nl.wikipedia.org
arbcom-ru.wikipedia.org
arc.m.wikipedia.orgMobile service
arc.wikipedia.org
ary.m.wikipedia.orgMobile service
ary.wikipedia.org
arz.m.wikipedia.orgMobile service
arz.wikipedia.org
as.m.wikipedia.orgMobile service
as.wikipedia.org
ast.m.wikipedia.orgMobile service
ast.wikipedia.org
atj.m.wikipedia.orgMobile service
atj.wikipedia.org
av.m.wikipedia.orgMobile service
av.wikipedia.org
avk.m.wikipedia.orgMobile service
avk.wikipedia.org
awa.m.wikipedia.orgMobile service
awa.wikipedia.org
ay.m.wikipedia.orgMobile service
ay.wikipedia.org
az.m.wikipedia.orgMobile service
az.wikipedia.org
azb.m.wikipedia.orgMobile service
azb.wikipedia.org
ba.m.wikipedia.orgMobile service
ba.wikipedia.org
ban.m.wikipedia.orgMobile service
ban.wikipedia.org
bar.m.wikipedia.orgMobile service
bar.wikipedia.org
bat-smg.m.wikipedia.orgMobile service
bat-smg.wikipedia.org
bbc.m.wikipedia.orgMobile service
bbc.wikipedia.org
bcl.m.wikipedia.orgMobile service
bcl.wikipedia.org
bdr.m.wikipedia.orgMobile service
bdr.wikipedia.org
be-tarask.m.wikipedia.orgMobile service
be-tarask.wikipedia.org
be-x-old.m.wikipedia.orgMobile service
be-x-old.wikipedia.org
be.m.wikipedia.orgMobile service
be.wikipedia.org
bew.m.wikipedia.orgMobile service
bew.wikipedia.org
bg.m.wikipedia.orgMobile service
bg.wikipedia.org
bh.m.wikipedia.orgMobile service
bh.wikipedia.org
bi.m.wikipedia.orgMobile service
bi.wikipedia.org
bjn.m.wikipedia.orgMobile service
bjn.wikipedia.org
blk.m.wikipedia.orgMobile service
blk.wikipedia.org
bm.m.wikipedia.orgMobile service
bm.wikipedia.org
bn.m.wikipedia.orgMobile service
bn.wikipedia.org
bo.m.wikipedia.orgMobile service
bo.wikipedia.org
bpy.m.wikipedia.orgMobile service
bpy.wikipedia.org
br.m.wikipedia.orgMobile service
br.wikipedia.org
bs.m.wikipedia.orgMobile service
bs.wikipedia.org
btm.m.wikipedia.orgMobile service
btm.wikipedia.org
bug.m.wikipedia.orgMobile service
bug.wikipedia.org
bugzilla.wikipedia.org
bxr.m.wikipedia.orgMobile service
bxr.wikipedia.org
ca.m.wikipedia.orgMobile service
ca.wikipedia.org
careers.wikipedia.org
cbk-zam.m.wikipedia.orgMobile service
cbk-zam.wikipedia.org
cdo.m.wikipedia.orgMobile service
cdo.wikipedia.org
ce.m.wikipedia.orgMobile service
ce.wikipedia.org
ceb.m.wikipedia.orgMobile service
ceb.wikipedia.org
ch.m.wikipedia.orgMobile service
ch.wikipedia.org
cho.m.wikipedia.orgMobile service
cho.wikipedia.org
chr.m.wikipedia.orgMobile service
chr.wikipedia.org
chy.m.wikipedia.orgMobile service
chy.wikipedia.org
ckb.m.wikipedia.orgMobile service
ckb.wikipedia.org
co.m.wikipedia.orgMobile service
co.wikipedia.org
commons.wikipedia.org
cr.m.wikipedia.orgMobile service
cr.wikipedia.org
crh.m.wikipedia.orgMobile service
crh.wikipedia.org
cs.m.wikipedia.orgMobile service
cs.wikipedia.org
csb.m.wikipedia.orgMobile service
csb.wikipedia.org
cu.m.wikipedia.orgMobile service
cu.wikipedia.org
cv.m.wikipedia.orgMobile service
cv.wikipedia.org
cy.m.wikipedia.orgMobile service
cy.wikipedia.org
da.m.wikipedia.orgMobile service
da.wikipedia.org
dag.m.wikipedia.orgMobile service
dag.wikipedia.org
de.m.wikipedia.orgMobile service
de.wikipedia.org
dga.m.wikipedia.orgMobile service
dga.wikipedia.org
din.m.wikipedia.orgMobile service
din.wikipedia.org
diq.m.wikipedia.orgMobile service
diq.wikipedia.org
dk.m.wikipedia.orgMobile service
dk.wikipedia.org
donate.wikipedia.org
download.wikipedia.orgStorage
dsb.m.wikipedia.orgMobile service
dsb.wikipedia.org
dtp.m.wikipedia.orgMobile service
dtp.wikipedia.org
dty.m.wikipedia.orgMobile service
dty.wikipedia.org
dv.m.wikipedia.orgMobile service
dv.wikipedia.org
dz.m.wikipedia.orgMobile service
dz.wikipedia.org
ee.m.wikipedia.orgMobile service
ee.wikipedia.org
el.m.wikipedia.orgMobile service
el.wikipedia.org
eml.m.wikipedia.orgMobile service
eml.wikipedia.org
en.m.wikipedia.orgMobile service
en.wikipedia.org
eo.wikipedia.org
epo.wikipedia.org
es.wikipedia.org
et.wikipedia.org
eu.wikipedia.org
ext.wikipedia.org
fa.wikipedia.org
fat.wikipedia.org
ff.wikipedia.org
fi.wikipedia.org
fiu-vro.wikipedia.org
fj.wikipedia.org
fo.wikipedia.org
fon.wikipedia.org
fr.wikipedia.org
frp.wikipedia.org
frr.wikipedia.org
fur.wikipedia.org
fy.wikipedia.org
ga.wikipedia.org
gag.wikipedia.org
gan.wikipedia.org
gcr.wikipedia.org
gd.wikipedia.org
gl.wikipedia.org
glk.wikipedia.org
gn.wikipedia.org
gom.wikipedia.org
gor.wikipedia.org
got.wikipedia.org
gpe.wikipedia.org
gu.wikipedia.org
guc.wikipedia.org
gur.wikipedia.org
guw.wikipedia.org
gv.wikipedia.org
ha.wikipedia.org
hak.wikipedia.org
haw.wikipedia.org
he.wikipedia.org
hi.wikipedia.org
hif.wikipedia.org
ho.wikipedia.org
hr.wikipedia.org
hsb.wikipedia.org
ht.wikipedia.org
hu.wikipedia.org
hy.wikipedia.org
hyw.wikipedia.org
hz.wikipedia.org
ia.wikipedia.org
iba.wikipedia.org
id.wikipedia.org
ie.wikipedia.org
ig.wikipedia.org
igl.wikipedia.org
ii.wikipedia.org
ik.wikipedia.org
ilo.wikipedia.org
inh.wikipedia.org
io.wikipedia.org
is.wikipedia.org
it.wikipedia.org
iu.wikipedia.org
ja.wikipedia.org
jam.wikipedia.org
jbo.wikipedia.org
jp.wikipedia.org
jv.wikipedia.org
ka.wikipedia.org
kaa.wikipedia.org
kab.wikipedia.org
kai.wikipedia.org
kaj.wikipedia.org
kbd.wikipedia.org
kbp.wikipedia.org
kcg.wikipedia.org
kg.wikipedia.org
kge.wikipedia.org
khw.wikipedia.org
ki.wikipedia.org
kj.wikipedia.org
kk.wikipedia.org
kl.wikipedia.org
km.wikipedia.org
kn.wikipedia.org
knc.wikipedia.org
ko.wikipedia.org
koi.wikipedia.org
kr.wikipedia.org
krc.wikipedia.org
ks.wikipedia.org
ksh.wikipedia.org
ku.wikipedia.org
kus.wikipedia.org
kv.wikipedia.org
kw.wikipedia.org
ky.wikipedia.org
la.wikipedia.org
lad.wikipedia.org
lb.wikipedia.org
lbe.wikipedia.org
lez.wikipedia.org
lfn.wikipedia.org
lg.wikipedia.org
li.wikipedia.org
lij.wikipedia.org
lld.wikipedia.org
lmo.wikipedia.org
ln.wikipedia.org
lo.wikipedia.org
lrc.wikipedia.org
lt.wikipedia.org
ltg.wikipedia.org
lv.wikipedia.org
lzh.wikipedia.org
m.wikipedia.orgMobile service
mad.wikipedia.org
mai.wikipedia.org
mail.wikipedia.orgEmail system
map-bms.wikipedia.org
mdf.wikipedia.org
meta.wikipedia.org
mg.wikipedia.org
mh.wikipedia.org
mhr.wikipedia.org
mi.wikipedia.org
min.wikipedia.org
mk.wikipedia.org
ml.wikipedia.org
mn.wikipedia.org
mni.wikipedia.org
mnw.wikipedia.org
mo.wikipedia.org
mos.wikipedia.org
mr.wikipedia.org
mrj.wikipedia.org
ms.wikipedia.org
mt.wikipedia.org
mus.wikipedia.org
mwl.wikipedia.org
my.wikipedia.org
myv.wikipedia.org
mzn.wikipedia.org
na.wikipedia.org
nah.wikipedia.org
nan.wikipedia.org
nap.wikipedia.org
nb.wikipedia.org
nds-nl.wikipedia.org
nds.wikipedia.org
ne.wikipedia.org
new.wikipedia.org
ng.wikipedia.org
nia.wikipedia.org
nl.wikipedia.org
nn.wikipedia.org
no.wikipedia.org
nostalgia.wikipedia.org
nov.wikipedia.org
nqo.wikipedia.org
nr.wikipedia.org
nrm.wikipedia.org
nso.wikipedia.org
nup.wikipedia.org
nv.wikipedia.org
ny.wikipedia.org
oc.wikipedia.org
olo.wikipedia.org
om.wikipedia.org
or.wikipedia.org
os.wikipedia.org
pa.wikipedia.org
pag.wikipedia.org
pam.wikipedia.org
pap.wikipedia.org
pcd.wikipedia.org
pcm.wikipedia.org
pdc.wikipedia.org
pfl.wikipedia.org
pi.wikipedia.org
pih.wikipedia.org
pl.wikipedia.org
pms.wikipedia.org
pnb.wikipedia.org
pnt.wikipedia.org
ppl.wikipedia.org
ps.wikipedia.org
pt.wikipedia.org
pwn.wikipedia.org
qu.wikipedia.org
quality.wikipedia.org
quote.wikipedia.org
rki.wikipedia.org
rm.wikipedia.org
rmy.wikipedia.org
rn.wikipedia.org
ro.wikipedia.org
roa-rup.wikipedia.org
roa-tara.wikipedia.org
rsk.wikipedia.org
ru.wikipedia.org
rue.wikipedia.org
rw.wikipedia.org
sa.wikipedia.org
sah.wikipedia.org
sat.wikipedia.org
sc.wikipedia.org
scn.wikipedia.org
sco.wikipedia.org
sd.wikipedia.org
se.wikipedia.org
sep11.wikipedia.org
sg.wikipedia.org
sh.wikipedia.org
shi.wikipedia.org
shn.wikipedia.org
shop.wikipedia.orgCommerce
shy.wikipedia.org
si.wikipedia.org
simple.wikipedia.org
sk.wikipedia.org
skr.wikipedia.org
sl.wikipedia.org
sm.wikipedia.org
smn.wikipedia.org
sn.wikipedia.org
so.wikipedia.org
sources.wikipedia.org
species.wikipedia.org
sq.wikipedia.org
sr.wikipedia.org
srn.wikipedia.org
ss.wikipedia.org
st.wikipedia.org
stats.wikipedia.orgAnalytics
store.wikipedia.orgCommerce
stq.wikipedia.org
su.wikipedia.org
sv.wikipedia.org
sw.wikipedia.org
syl.wikipedia.org
sysop-it.wikipedia.org
szl.wikipedia.org
szy.wikipedia.org
ta.wikipedia.org
tay.wikipedia.org
tcy.wikipedia.org
tdd.wikipedia.org
te.wikipedia.org
ten.wikipedia.org
test2.wikipedia.org
tet.wikipedia.org
textbook.wikipedia.org
tg.wikipedia.org
th.wikipedia.org
thankyou.wikipedia.org
ti.wikipedia.org
tig.wikipedia.org
tk.wikipedia.org
tl.wikipedia.org
tly.wikipedia.org
tn.wikipedia.org
to.wikipedia.org
tok.wikipedia.org
tokipona.wikipedia.org
tpi.wikipedia.org
tr.wikipedia.org
trv.wikipedia.org
ts.wikipedia.org
tt.wikipedia.org
tum.wikipedia.org
tw.wikipedia.org
ty.wikipedia.org
tyv.wikipedia.org
udm.wikipedia.org
ug.wikipedia.org
uk.wikipedia.org
ur.wikipedia.org
uz.wikipedia.org
ve.wikipedia.org
vec.wikipedia.org
vep.wikipedia.org
vi.wikipedia.org
vls.wikipedia.org
vo.wikipedia.org
wa.wikipedia.org
war.wikipedia.org
wg-en.wikipedia.org
wo.wikipedia.org
wuu.wikipedia.org
www.wikipedia.org
xal.wikipedia.org
xh.wikipedia.org
xmf.wikipedia.org
yi.wikipedia.org
yo.wikipedia.org
yue.wikipedia.org
za.wikipedia.org
zea.wikipedia.org
zero.wikipedia.org
zgh.wikipedia.org
zh-classical.wikipedia.org
zh-min-nan.wikipedia.org
zh-tw.wikipedia.org
zh-yue.wikipedia.org
zh.wikipedia.org
zu.wikipedia.org
Final URL
https://www.wikipedia.org/
Website rankings and industry category are based on data from Similarweb
CVE-2026-58179
Apache Traffic Server 9.2.13
CVSS 9.8
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
The Apache Traffic Server regex_remap plugin overflows the stack and integers from substitution input.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58185Apache Traffic Server 9.2.13CVSS 9.8
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
The Apache Traffic Server intercept plugin has a use-after-free.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58154Apache Traffic Server 9.2.13CVSS 9.2
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
Apache Traffic Server can write out of bounds or overflow integers while parsing MIME and HTTP headers.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58155Apache Traffic Server 9.2.13CVSS 9.2
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
Apache Traffic Server truncates over-long header names, allowing header aliasing, request smuggling, and policy bypass.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58161Apache Traffic Server 9.2.13CVSS 9.2
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
Apache Traffic Server can crash from null dereferences and dangling references in TLS and SNI handling.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-33267Apache Traffic Server 9.2.13CVSS 9.1
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
Improper Input Validation vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.2.0 through 9.2.14, from 10.1.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fixes the issue.
CVE-2026-58163Apache Traffic Server 9.2.13CVSS 9.1
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
Apache Traffic Server mishandles on-disk cache fields and object lifetimes, corrupting state or crashing.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58151Apache Traffic Server 9.2.13CVSS 8.7
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58162Apache Traffic Server 9.2.13CVSS 8.4
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
The Apache Traffic Server certifier plugin generates certificates based on attacker-controlled client SNI.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58188Apache Traffic Server 9.2.13CVSS 8.4
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
Several Apache Traffic Server experimental plugins have memory-safety and limit-bypass errors.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58164Apache Traffic Server 9.2.13CVSS 8.3
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
Apache Traffic Server has use-after-free and time-of-check/time-of-use errors in remap configuration handling.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-33930Apache Traffic Server 9.2.13CVSS 8.2
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
Apache Traffic Server copies the client Host header into a fixed-size stack buffer without a bound during redirect handling, so an over-long Host header overflows the stack when redirect following is enabled.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58158Apache Traffic Server 9.2.13CVSS 8.2
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
Apache Traffic Server mishandles PROXY protocol input, truncating ports and overflowing the stack.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58175Apache Traffic Server 9.2.13CVSS 8.2
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
Apache Traffic Server leaks memory when handling HostDB SRV records.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58178Apache Traffic Server 9.2.13CVSS 8.2
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
The Apache Traffic Server ESI plugin can recurse without bound and fetch attacker-controlled URLs.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58180Apache Traffic Server 9.2.13CVSS 8.2
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
The Apache Traffic Server txn_box plugin overflows the stack from attacker-controlled input.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58181Apache Traffic Server 9.2.13CVSS 8.2
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
The Apache Traffic Server uri_signing and url_sig plugins can exhaust the stack or crash on attacker input.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58182Apache Traffic Server 9.2.13CVSS 8.2
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58186Apache Traffic Server 9.2.13CVSS 8.2
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58189Apache Traffic Server 9.2.13CVSS 8.2
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
Apache Traffic Server allows redirect-limit bypass when plugins reset the retry counter, enabling SSRF amplification.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-65324Apache Traffic Server 9.2.13CVSS 8.2
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
Apache Traffic Server drops the per-stream buffer cap when dechunking HTTP/2 or HTTP/3 responses, letting a slow client exhaust server memory.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58150Apache Traffic Server 9.2.13CVSS 7.8
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
Apache Traffic Server does not reject Transfer-Encoding in HTTP/2 requests, allowing downgrade request smuggling.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58183Apache Traffic Server 9.2.13CVSS 7.5
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
The Apache Traffic Server prefetch plugin can crash when processing attacker-influenced input.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-58184Apache Traffic Server 9.2.13CVSS 7.5
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
The Apache Traffic Server header_rewrite plugin can crash or corrupt memory during cookie operations and CIDR condition matching.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVE-2026-59173Apache Traffic Server 9.2.13CVSS 7.5
Matched product: Apache Traffic Server 9.2.13 Confidence: Medium
Uncontrolled Resource Consumption vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2.
Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue.