CVE-2026-65100
Apache Traffic Server vulnerability analysis and mitigation

Overview

CVE-2026-65100 is an HTTP/2 HPACK encoder desynchronization vulnerability in Apache Traffic Server (ATS) that allows unauthenticated network attackers to corrupt HTTP/2 header blocks on affected connections. The root cause is that ATS updates the HPACK dynamic table before confirming a successful header block encoding, leaving the encoder out of sync with the peer decoder upon encode failure. Affected versions include 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. It was published on July 29, 2026, and carries a CVSS v3.1 base score of 4.8 (Medium) and a CVSS v4.0 base score of 6.3 (Medium) (GitHub Advisory, Red Hat Bugzilla).

Technical details

The vulnerability is classified as CWE-696 (Incorrect Behavior Order): ATS updates the HTTP/2 HPACK dynamic table state before verifying that the header block was encoded successfully (GitHub Advisory). When an encoding failure occurs, the encoder's internal state diverges from the peer decoder's expected state, causing all subsequent header blocks on that connection to be corrupted or misinterpreted. Exploitation requires no authentication or user interaction, but does require specific attack conditions (AT:P in CVSS v4.0 terminology) — namely, an active HTTP/2 connection to the vulnerable ATS instance where an encoding failure can be triggered. No public proof-of-concept code has been identified (GitHub Advisory).

Impact

Successful exploitation causes the HPACK encoder and decoder to become desynchronized, corrupting all subsequent HTTP/2 header blocks on the affected connection. This results in a denial-of-service condition for that connection, breaking HTTP/2 communications between the client and the ATS proxy. The integrity impact is low (affecting subsequent system integrity via corrupted headers), and there is no confidentiality impact or direct data exfiltration risk. The vulnerability does not enable remote code execution or lateral movement (GitHub Advisory, Red Hat Bugzilla).

Exploitability

There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.25–0.45%, indicating a low near-term exploitation probability. NVD's SSVC assessment classifies exploitation as "none" and the vulnerability as non-automatable with partial technical impact (Apache Mailing List).

Mitigation and workarounds

Apache recommends upgrading Apache Traffic Server to version 9.2.15 or 10.1.4, which contain the fix for this issue (GitHub Advisory, Apache Mailing List). No patch is available for the 8.x branch, so users on versions 8.0.0–8.1.9 should migrate to a supported release (9.2.15 or 10.1.4). As a temporary measure, operators may consider disabling HTTP/2 on affected ATS instances if upgrading immediately is not feasible, though this will impact performance and protocol compatibility.

Community reactions

Red Hat has tracked this vulnerability via Bugzilla (Bug 2508354) and assigned it medium severity, with dependent tracking bugs for affected Red Hat products (Red Hat Bugzilla). The Apache Software Foundation disclosed the issue via its security mailing list and GitHub Advisory Database (Apache Mailing List). No notable independent researcher commentary or significant social media discussion has been identified beyond standard CVE aggregator coverage.

Additional resources


SourceThis report was generated using AI

Related Apache Traffic Server vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-58188HIGH8.4
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver
NoYesJul 29, 2026
CVE-2026-58189HIGH8.2
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver
NoYesJul 29, 2026
CVE-2026-58186HIGH8.2
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver
NoYesJul 29, 2026
CVE-2026-65100MEDIUM6.3
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver-devel
NoYesJul 29, 2026
CVE-2026-58187MEDIUM6.3
  • Apache Traffic Server logoApache Traffic Server
  • trafficserver9
NoYesJul 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management