https://seclists.org/oss-sec/2026/q3/162: CVE-2026-59173: Apache Traffic Server is vulnerable to stalled HTTP/2 flow-control
Published Jul 17, 2026
·Updated
Affected Software
1 affected component
Apache Software Foundation Apache Traffic Server>=9.0.0<=9.2.13, >=10.0.0<=10.1.2
Frequently Asked Questions
1
What is the severity of CVE-2026-59173?
The severity of CVE-2026-59173 is classified as important.
2
How do I fix CVE-2026-59173?
To resolve CVE-2026-59173, update Apache Traffic Server to a version beyond 10.1.2 or 9.2.13.
3
Which versions of Apache Traffic Server are affected by CVE-2026-59173?
CVE-2026-59173 affects Apache Traffic Server versions 9.0.0 to 9.2.13 and 10.0.0 to 10.1.2.
4
What kind of attack can exploit CVE-2026-59173?
CVE-2026-59173 can be exploited to carry out a Denial of Service (DoS) attack via stalled HTTP/2 flow-control conditions.
5
Who reported CVE-2026-59173?
CVE-2026-59173 was reported by the Okta Red Team.