CVE-2026-59173

7.5

Apache Software Foundation · Apache Traffic Server

Apache Traffic Server is vulnerable to uncontrolled resource consumption, which may lead to a denial of service via stalled HTTP/2 flow-control.

Executive summary

Apache Traffic Server is susceptible to a denial of service vulnerability that could disrupt network traffic availability.

Vulnerability

This is an uncontrolled resource consumption flaw (CWE-400) allowing an unauthenticated remote attacker to cause a denial of service condition by exploiting stalled HTTP/2 flow-control.

Business impact

A successful exploit results in the degradation or total loss of service availability for the affected traffic server. With a CVSS score of 7.5, this high-severity vulnerability poses a significant risk to business continuity, particularly for organizations relying on this software for high-volume content delivery or proxy services.

Remediation

Immediate Action: Upgrade to version 9.1.14 or 10.1.3 immediately to incorporate the necessary flow-control patches.

Proactive Monitoring: Monitor server resource utilization and review access logs for unusual patterns or spikes in HTTP/2 traffic that may indicate exploitation attempts.

Compensating Controls: Deploy a Web Application Firewall or rate-limiting rules to filter malformed or excessive HTTP/2 traffic until the patch can be applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The high-severity nature of this denial of service vulnerability mandates immediate attention. Administrators should prioritize updating to the patched versions to eliminate the risk of service disruption.

More Apache Software Foundation CVEs