Executive brief
Apache Traffic Server, a high-performance caching proxy used to manage web traffic, is vulnerable to a denial-of-service attack. By sending specially crafted HTTP/2 messages, an attacker can crash the server or exhaust its resources. This can lead to service outages, preventing legitimate users from accessing websites or applications behind the proxy.
Technical details
This vulnerability is classified as Uncontrolled Resource Consumption (CWE-400) within the HTTP/2 implementation of Apache Traffic Server. An unauthenticated remote attacker can exploit this by sending abusive HTTP/2 frames and manipulating flow-control mechanisms. This activity can lead to a process crash or complete resource exhaustion, resulting in a denial-of-service (DoS) condition. The issue affects versions 8.x, 9.x, and 10.x, and is resolved in versions 9.2.15 and 10.1.4.
Affected products
- Apache Traffic Server 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, 10.0.0 through 10.1.3
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory