VDB
CVE-2026-59173
CVE-2026-59173
PUBLISHED
CVSS 7.5 HIGH
Reported by apache · Published July 18, 2026
Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache Software Foundation | Apache Traffic Server | 9.0.0, 10.0.0 |
| Apache Software Foundation | Apache Traffic Server | 9.0.0, 10.0.0, 9.0.0 |
Timeline
- Jul 17, 2026 CVE Published
- Jul 17, 2026 Security Advisory
- Jul 19, 2026 Security Advisory
References
- vendor-advisory
- http://www.openwall.com/lists/oss-security/2026/07/17/5 url