
PEACH
Un cadre d’isolation des locataires
CVE-2026-59173 is a denial-of-service vulnerability in Apache Traffic Server (ATS) caused by stalled HTTP/2 flow-control conditions. A remote, unauthenticated attacker can exploit this flaw to exhaust worker/connection resources and, under high limits, trigger unbounded memory amplification leading to OOM kills or system unresponsiveness. Affected versions include ATS 9.0.0 through 9.2.13 and ATS 10.0.0 through 10.1.2. The vulnerability was reported by the Okta Red Team and disclosed on July 16–17, 2026, with a severity rating of "important" by the Apache Software Foundation (OSS-Sec). Feedly estimates the CVSS category as Medium (Feedly).
The vulnerability (CWE classification not yet formally assigned) stems from improper handling of HTTP/2 flow-control window management in Apache Traffic Server. An attacker can craft HTTP/2 requests that intentionally stall flow-control, preventing the server from draining connection/worker resources, which accumulates over time. Under configurations with high connection or memory limits, this stalling can cause unbounded memory amplification, ultimately resulting in out-of-memory (OOM) kills or complete system unresponsiveness. No authentication is required to trigger the condition (OSS-Sec).
Successful exploitation results in a denial-of-service condition affecting the availability of the Apache Traffic Server instance. Attackers can exhaust worker threads and connection resources, and in high-limit configurations, drive the server to OOM termination or full system unresponsiveness, disrupting all proxied traffic. There is no direct confidentiality or integrity impact reported, but prolonged unavailability of a reverse proxy or CDN node could have significant downstream effects on dependent services (OSS-Sec).
traffic_server); OOM killer events in system logs (/var/log/syslog or dmesg) referencing the ATS process.Apache has released patched versions addressing this vulnerability: ATS 9.x users should upgrade to 9.2.14 or later, and ATS 10.x users should upgrade to 10.1.3 or later. No configuration-based workaround has been officially documented; upgrading to the fixed release is the recommended and prioritized remediation. Operators unable to upgrade immediately should consider rate-limiting HTTP/2 connections and enforcing strict connection/stream limits as a temporary defensive measure (OSS-Sec).
The vulnerability was reported by the Okta Red Team, indicating active security research engagement with Apache Traffic Server. Discussion appeared on the oss-security mailing list shortly after disclosure, and the issue was noted on Bluesky by the infosec community (OSS-Sec, OSV). No major vendor statements beyond the Apache disclosure or significant media coverage have been identified at this time.
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."