HIGH
Apache Traffic Server: Abusive HTTP/2 framing can exhaust resources and crash the server
Published Jul 29, 2026
8.7
HIGHCVSS 4.0
EPSS 0.66%
Description
Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected products
-
Affected
- ≥ 10.0.0, ≤ 10.1.3
- ≥ 8.0.0, ≤ 8.1.11
- ≥ 9.0.0, ≤ 9.2.14
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Apache Software Foundation | Apache Traffic Server | unaffected | Affected
|
OR
- ≥ 8.0.0 · ≤ 8.1.9
- ≥ 9.0.0 · < 9.2.15
- ≥ 10.0.0 · < 10.1.4
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-50203 Advisory
- https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d vendor-advisoryVendor AdvisoryMailing List
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-50203 | Advisory | |
| https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d | vendor-advisoryVendor AdvisoryMailing List |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jul 29, 2026
Updated Oct 1, 2026
Reserved Jun 29, 2026
Link CVE-2026-58151
CISA Vulnrichment
Updated Jul 29, 2026
Red Hat
No data
GitHub
No data