CVE-2026-59173: Apache Traffic Server: DoS vulnerability in HTTP/2 via stalled flow-control conditions
Uncontrolled Resource Consumption vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2.
Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 9.1.14 - Upgrade
Upgrade
Apache Traffic Serverto a version that resolves this vulnerability.Fixed in 10.1.3
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59173?
CVE-2026-59173 has a risk rating of 32, indicating a significant level of vulnerability.
How do I fix CVE-2026-59173?
To fix CVE-2026-59173, upgrade Apache Traffic Server to version 9.1.14 or 10.1.3.
Which versions of Apache Traffic Server are affected by CVE-2026-59173?
CVE-2026-59173 affects Apache Traffic Server versions from 9.0.0 through 9.1.13 and from 10.0.0 through 10.1.2.
What type of vulnerability is CVE-2026-59173?
CVE-2026-59173 is an uncontrolled resource consumption vulnerability that can lead to a denial of service.
When was CVE-2026-59173 published?
CVE-2026-59173 was published on July 17, 2026.