Junglewise Threat Intelligence

CVE-2026-59173: Apache Traffic Server uncontrolled resource consumption

CVE-2026-59173 · Severity: info · Published 2026-07-18

Technologies: Apache Traffic Server. Vendors: Apache.

Executive brief

Apache Traffic Server, a high-performance caching proxy used to manage web traffic and improve website delivery, is vulnerable to a resource consumption issue. An attacker could potentially exploit this to exhaust system resources, leading to a denial-of-service condition where the server becomes unresponsive to legitimate users. Organizations using affected versions should upgrade to the latest patched releases to maintain service availability.

Technical details

A vulnerability classified as CWE-400 (Uncontrolled Resource Consumption) exists in Apache Traffic Server versions 9.0.0 through 9.1.13 and 10.0.0 through 10.1.2. The flaw allows a remote attacker to trigger excessive consumption of system resources, potentially leading to service degradation or a complete crash (Denial of Service). While specific exploitation details are not provided in the advisory, such vulnerabilities typically involve sending specially crafted network requests that the server fails to process efficiently. The issue is resolved in versions 9.1.14 and 10.1.3.

Affected products

  • Apache Traffic Server 9.0.0 through 9.1.13, 10.0.0 through 10.1.2

Timeline

  • 2026-07-18: disclosed
  • 2026-07-18: advisory

References

Related threats