Executive brief
Apache Traffic Server, a high-performance caching proxy used to manage web traffic, contains a vulnerability in its Lua scripting plugin. This flaw could allow an attacker to disrupt the service or potentially access sensitive information by exploiting how the system handles script initialization and data transformations. Organizations using this software should upgrade to the latest versions to prevent potential service outages or data leaks.
Technical details
A vulnerability exists in the ts_lua plugin of Apache Traffic Server due to improper management of initialization, transform context, and per-instance state. Classified under CWE-400 (Uncontrolled Resource Consumption), the flaw allows a remote attacker to trigger state inconsistencies or resource exhaustion via network requests. The root cause stems from how the plugin handles Lua script execution environments and data transformation contexts. Successful exploitation can lead to high availability impact and low confidentiality/integrity impacts. Patches are available in versions 9.2.15 and 10.1.4.
Affected products
- Apache Traffic Server 8.0.0 - 8.1.9, 9.0.0 - 9.2.14, 10.0.0 - 10.1.3
Timeline
- 2026-07-29: disclosed
- 2026-07-29: advisory