Junglewise Threat Intelligence

CVE-2026-58151: Apache Traffic Server resource exhaustion via HTTP/2 framing

CVE-2026-58151 · Severity: high · CVSS 7.5 · Published 2026-07-29

Technologies: Apache Traffic Server. Vendors: Apache.

Executive brief

Apache Traffic Server, a high-performance caching proxy used to manage web traffic, is vulnerable to a denial-of-service attack. By sending specially crafted HTTP/2 messages, an attacker can crash the server or exhaust its resources. This can lead to service outages, preventing legitimate users from accessing websites or applications behind the proxy.

Technical details

This vulnerability is classified as Uncontrolled Resource Consumption (CWE-400) within the HTTP/2 implementation of Apache Traffic Server. An unauthenticated remote attacker can exploit this by sending abusive HTTP/2 frames and manipulating flow-control mechanisms. This activity can lead to a process crash or complete resource exhaustion, resulting in a denial-of-service (DoS) condition. The issue affects versions 8.x, 9.x, and 10.x, and is resolved in versions 9.2.15 and 10.1.4.

Affected products

  • Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory

References

Related threats