CVE-2026-59173

Apache Software Foundation · Apache Traffic Server

Apache Traffic Server is vulnerable to uncontrolled resource consumption, which may lead to a denial of service via stalled HTTP/2 flow-control.

Executive summary

Apache Traffic Server is susceptible to a denial of service vulnerability that could disrupt network traffic availability.

Vulnerability

This is an uncontrolled resource consumption flaw (CWE-400) allowing an unauthenticated remote attacker to cause a denial of service condition by exploiting stalled HTTP/2 flow-control.

Business impact

A successful exploit results in the degradation or total loss of service availability for the affected traffic server. With a CVSS score of 7.5, this high-severity vulnerability poses a significant risk to business continuity, particularly for organizations relying on this software for high-volume content delivery or proxy services.

Remediation

Immediate Action: Upgrade to version 9.1.14 or 10.1.3 immediately to incorporate the necessary flow-control patches.

Proactive Monitoring: Monitor server resource utilization and review access logs for unusual patterns or spikes in HTTP/2 traffic that may indicate exploitation attempts.

Compensating Controls: Deploy a Web Application Firewall or rate-limiting rules to filter malformed or excessive HTTP/2 traffic until the patch can be applied.

Exploitation status

Public Exploit Available: No

Analyst recommendation

The high-severity nature of this denial of service vulnerability mandates immediate attention. Administrators should prioritize updating to the patched versions to eliminate the risk of service disruption.