Description
Uncontrolled Resource Consumption vulnerability in Apache Traffic Server.

This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2.

Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue.
Published: 2026-07-18
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Identified in Apache Traffic Server is a DoS vulnerability that arises from stalled flow‑control conditions in HTTP/2. The flaw allows an attacker to send crafted requests that cause the server to consume excessive resources without delivering payloads, leading to service degradation or disconnection. The weakness is categorized as CWE‑400, reflecting an attempt to overwhelm the target’s resource limits.

Affected Systems

Affected versions are Apache Traffic Server 9.0.0 through 9.1.13 and 10.0.0 through 10.1.2. The vulnerability is not present in 9.1.14 or later, nor in 10.1.3 or later.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity, but the EPSS score is below 1%, suggesting low exploitation probability at present. It is not listed in the CISA KEV catalog. Exploitation would most likely require an outbound or transparent connection to a victim that accepts HTTP/2 traffic and can sustain the unstable flow‑control state. No confirmed public exploits have been reported, but the damage potential remains significant for exposed services.

Generated by OpenCVE AI on July 30, 2026 at 23:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Traffic Server to version 9.1.14 or 10.1.3, which includes the fix for the stalled flow‑control issue.
  • If HTTP/2 is not required for business operations, temporarily disable the protocol to avoid the vulnerability until the upgrade is completed.
  • Continuously monitor server logs for errors related to stalled flow‑control conditions and apply defensive traffic shaping or rate limiting as a supplementary measure.

Generated by OpenCVE AI on July 30, 2026 at 23:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 21 Jul 2026 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apache Traffic Server
Vendors & Products Apache
Apache apache Traffic Server

Mon, 20 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 18 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue.
Title Apache Traffic Server: DoS vulnerability in HTTP/2 via stalled flow-control conditions
Weaknesses CWE-400
References

Subscriptions

Apache Apache Traffic Server
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-07-20T13:41:03.319Z

Reserved: 2026-07-02T17:22:51.439Z

Link: CVE-2026-59173

cve-icon Vulnrichment

Updated: 2026-07-18T13:33:30.084Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T23:15:06Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption