CVE-2026-58151: Apache Traffic Server: Abusive HTTP/2 framing can exhaust resources and crash the server
Apache Traffic Server can be crashed or driven to resource exhaustion by abusive HTTP/2 framing and flow-control.
This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.
Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.2.15 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.4
Event History
Frequently Asked Questions
What is the severity of CVE-2026-58151?
The severity of CVE-2026-58151 is rated as high, with a score of 7.5.
What problems can CVE-2026-58151 cause?
CVE-2026-58151 can lead to server crashes or resource exhaustion due to abusive HTTP/2 framing.
How do I fix CVE-2026-58151?
To fix CVE-2026-58151, upgrade your Apache Traffic Server to version 9.2.15 or 10.1.4.
Which versions of Apache Traffic Server are affected by CVE-2026-58151?
CVE-2026-58151 affects Apache Traffic Server versions from 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3.
Is it safe to continue using Apache Traffic Server with CVE-2026-58151?
No, it is not safe to continue using affected versions of Apache Traffic Server due to the high risk of crashes and resource exhaustion.