Impact
Identified in Apache Traffic Server is a DoS vulnerability that arises from stalled flow‑control conditions in HTTP/2. The flaw allows an attacker to send crafted requests that cause the server to consume excessive resources without delivering payloads, leading to service degradation or disconnection. The weakness is categorized as CWE‑400, reflecting an attempt to overwhelm the target’s resource limits.
Affected Systems
Affected versions are Apache Traffic Server 9.0.0 through 9.1.13 and 10.0.0 through 10.1.2. The vulnerability is not present in 9.1.14 or later, nor in 10.1.3 or later.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity, but the EPSS score is below 1%, suggesting low exploitation probability at present. It is not listed in the CISA KEV catalog. Exploitation would most likely require an outbound or transparent connection to a victim that accepts HTTP/2 traffic and can sustain the unstable flow‑control state. No confirmed public exploits have been reported, but the damage potential remains significant for exposed services.
OpenCVE Enrichment