CVE-2026-59173
Apache Traffic Server Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-59173 is a denial-of-service vulnerability in Apache Traffic Server (ATS) caused by stalled HTTP/2 flow-control conditions. A remote, unauthenticated attacker can exploit this flaw to exhaust worker/connection resources and, under high limits, trigger unbounded memory amplification leading to OOM kills or system unresponsiveness. Affected versions include ATS 9.0.0 through 9.2.13 and ATS 10.0.0 through 10.1.2. The vulnerability was reported by the Okta Red Team and disclosed on July 16–17, 2026, with a severity rating of "important" by the Apache Software Foundation (OSS-Sec). Feedly estimates the CVSS category as Medium (Feedly).

Détails techniques

The vulnerability (CWE classification not yet formally assigned) stems from improper handling of HTTP/2 flow-control window management in Apache Traffic Server. An attacker can craft HTTP/2 requests that intentionally stall flow-control, preventing the server from draining connection/worker resources, which accumulates over time. Under configurations with high connection or memory limits, this stalling can cause unbounded memory amplification, ultimately resulting in out-of-memory (OOM) kills or complete system unresponsiveness. No authentication is required to trigger the condition (OSS-Sec).

Impact

Successful exploitation results in a denial-of-service condition affecting the availability of the Apache Traffic Server instance. Attackers can exhaust worker threads and connection resources, and in high-limit configurations, drive the server to OOM termination or full system unresponsiveness, disrupting all proxied traffic. There is no direct confidentiality or integrity impact reported, but prolonged unavailability of a reverse proxy or CDN node could have significant downstream effects on dependent services (OSS-Sec).

Étapes d’exploitation

  1. Reconnaissance: Identify internet-facing Apache Traffic Server instances running versions 9.0.0–9.2.13 or 10.0.0–10.1.2 using tools like Shodan or Censys, filtering for HTTP/2-enabled endpoints.
  2. Establish HTTP/2 connections: Open multiple HTTP/2 connections to the target ATS instance, leveraging the protocol's multiplexed stream capability.
  3. Stall flow-control windows: Send HTTP/2 requests but deliberately withhold WINDOW_UPDATE frames, causing the server's flow-control windows to reach zero and stalling data transmission on those streams.
  4. Amplify resource exhaustion: Repeat across many concurrent streams and connections to exhaust worker threads and connection slots; under high-limit configurations, this drives unbounded memory growth.
  5. Achieve DoS: Sustain the stalled connections until the server process is killed by the OS OOM killer or becomes fully unresponsive, denying service to legitimate clients (OSS-Sec).

Indicateurs de compromis

  • Network: High volume of long-lived HTTP/2 connections from one or few source IPs with minimal data transfer; connections that remain open without sending WINDOW_UPDATE frames.
  • Logs: Apache Traffic Server access/error logs showing a large number of stalled or hung HTTP/2 streams; repeated connection timeouts or resource exhaustion warnings in ATS logs.
  • Process: Rapidly increasing memory consumption by the ATS process (traffic_server); OOM killer events in system logs (/var/log/syslog or dmesg) referencing the ATS process.
  • System: Elevated load average with worker threads stuck in I/O wait; system unresponsiveness or ATS process crashes correlating with unusual HTTP/2 connection patterns (OSS-Sec).

Atténuation et solutions de contournement

Apache has released patched versions addressing this vulnerability: ATS 9.x users should upgrade to 9.2.14 or later, and ATS 10.x users should upgrade to 10.1.3 or later. No configuration-based workaround has been officially documented; upgrading to the fixed release is the recommended and prioritized remediation. Operators unable to upgrade immediately should consider rate-limiting HTTP/2 connections and enforcing strict connection/stream limits as a temporary defensive measure (OSS-Sec).

Réactions de la communauté

The vulnerability was reported by the Okta Red Team, indicating active security research engagement with Apache Traffic Server. Discussion appeared on the oss-security mailing list shortly after disclosure, and the issue was noted on Bluesky by the infosec community (OSS-Sec, OSV). No major vendor statements beyond the Apache disclosure or significant media coverage have been identified at this time.

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté Apache Traffic Server Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-59173HIGH7.5
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver
NonOuiJul 18, 2026
CVE-2025-65114HIGH7.5
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver-debugsource
NonOuiApr 02, 2026
CVE-2025-58136HIGH7.5
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver-debugsource
NonOuiApr 02, 2026
CVE-2025-49763HIGH7.5
  • Apache Traffic Server logoApache Traffic Server
  • cpe:2.3:a:apache:traffic_server
NonOuiJun 19, 2025
CVE-2025-31698HIGH7.5
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver-debugsource
NonOuiJun 19, 2025

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités