Apache Traffic Server Uncontrolled Resource Consumption Vulnerability Leading to HTTP/2 Denial-of-Service

Vulnerability

A denial-of-service vulnerability has been identified in Apache Traffic Server, specifically in the HTTP/2 protocol, where stalled flow-control can be exploited. This issue affects Apache Traffic Server versions 9.0.0 prior to 9.1.14 and 10.0.0 prior to 10.1.3.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition by causing stalled flow-control in HTTP/2, which can disrupt normal traffic management and processing.

Remediation

Users of Apache Traffic Server 9.x should upgrade to version 9.1.14 or later. Users of Apache Traffic Server 10.x should upgrade to version 10.1.3 or later.

Added: Jul 18, 2026, 1:22 PM
Updated: Jul 18, 2026, 1:22 PM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
2.5
exploitability
7.6
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.