CVE-2026-59173

CVE-2026-59173: Apache Traffic Server: DoS vulnerability in HTTP/2 via stalled flow-control conditions

Vendor Apache Software Foundation
Product Apache Traffic Server
Weakness CWE-400
Published July 18, 2026
Last update July 18, 2026

CVSS base score

What the vulnerability does

01Description

Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue.

Key dates

02Disclosure timeline

July 18, 2026 CVE published
July 18, 2026 Record updated