
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-65100 is an HTTP/2 HPACK encoder desynchronization vulnerability in Apache Traffic Server (ATS) that allows unauthenticated network attackers to corrupt HTTP/2 header blocks on affected connections. The root cause is that ATS updates the HPACK dynamic table before confirming a successful header block encoding, leaving the encoder out of sync with the peer decoder upon encode failure. Affected versions include 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. It was published on July 29, 2026, and carries a CVSS v3.1 base score of 4.8 (Medium) and a CVSS v4.0 base score of 6.3 (Medium) (GitHub Advisory, Red Hat Bugzilla).
The vulnerability is classified as CWE-696 (Incorrect Behavior Order): ATS updates the HTTP/2 HPACK dynamic table state before verifying that the header block was encoded successfully (GitHub Advisory). When an encoding failure occurs, the encoder's internal state diverges from the peer decoder's expected state, causing all subsequent header blocks on that connection to be corrupted or misinterpreted. Exploitation requires no authentication or user interaction, but does require specific attack conditions (AT:P in CVSS v4.0 terminology) — namely, an active HTTP/2 connection to the vulnerable ATS instance where an encoding failure can be triggered. No public proof-of-concept code has been identified (GitHub Advisory).
Successful exploitation causes the HPACK encoder and decoder to become desynchronized, corrupting all subsequent HTTP/2 header blocks on the affected connection. This results in a denial-of-service condition for that connection, breaking HTTP/2 communications between the client and the ATS proxy. The integrity impact is low (affecting subsequent system integrity via corrupted headers), and there is no confidentiality impact or direct data exfiltration risk. The vulnerability does not enable remote code execution or lateral movement (GitHub Advisory, Red Hat Bugzilla).
There is no evidence of public proof-of-concept exploit code or active in-the-wild exploitation at this time (GitHub Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.25–0.45%, indicating a low near-term exploitation probability. NVD's SSVC assessment classifies exploitation as "none" and the vulnerability as non-automatable with partial technical impact (Apache Mailing List).
Apache recommends upgrading Apache Traffic Server to version 9.2.15 or 10.1.4, which contain the fix for this issue (GitHub Advisory, Apache Mailing List). No patch is available for the 8.x branch, so users on versions 8.0.0–8.1.9 should migrate to a supported release (9.2.15 or 10.1.4). As a temporary measure, operators may consider disabling HTTP/2 on affected ATS instances if upgrading immediately is not feasible, though this will impact performance and protocol compatibility.
Red Hat has tracked this vulnerability via Bugzilla (Bug 2508354) and assigned it medium severity, with dependent tracking bugs for affected Red Hat products (Red Hat Bugzilla). The Apache Software Foundation disclosed the issue via its security mailing list and GitHub Advisory Database (Apache Mailing List). No notable independent researcher commentary or significant social media discussion has been identified beyond standard CVE aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."