CVE-2026-59173
Apache Software Foundation · Apache Traffic Server
Apache Traffic Server is vulnerable to uncontrolled resource consumption, which may lead to a denial of service via stalled HTTP/2 flow-control.
Executive summary
Apache Traffic Server is susceptible to a denial of service vulnerability that could disrupt network traffic availability.
Vulnerability
This is an uncontrolled resource consumption flaw (CWE-400) allowing an unauthenticated remote attacker to cause a denial of service condition by exploiting stalled HTTP/2 flow-control.
Business impact
A successful exploit results in the degradation or total loss of service availability for the affected traffic server. With a CVSS score of 7.5, this high-severity vulnerability poses a significant risk to business continuity, particularly for organizations relying on this software for high-volume content delivery or proxy services.
Remediation
Immediate Action: Upgrade to version 9.1.14 or 10.1.3 immediately to incorporate the necessary flow-control patches.
Proactive Monitoring: Monitor server resource utilization and review access logs for unusual patterns or spikes in HTTP/2 traffic that may indicate exploitation attempts.
Compensating Controls: Deploy a Web Application Firewall or rate-limiting rules to filter malformed or excessive HTTP/2 traffic until the patch can be applied.
Exploitation status
Public Exploit Available: No
Analyst recommendation
The high-severity nature of this denial of service vulnerability mandates immediate attention. Administrators should prioritize updating to the patched versions to eliminate the risk of service disruption.