Excessive Memory Consumption in ESI Plugin for Apache Traffic Server
CVE-2025-49763
7.5HIGH
What is CVE-2025-49763?
The ESI plugin for Apache Traffic Server presents a vulnerability due to the absence of a limit on the maximum inclusion depth. This oversight can lead to excessive memory consumption when malicious instructions are inserted into the system. Users of Apache Traffic Server are encouraged to leverage the newly introduced setting (--max-inclusion-depth) to impose this limit. The issue has been identified across various versions of Apache Traffic Server, including those from versions 9.0.0 to 9.2.10 and 10.0.0 to 10.0.5. To mitigate this risk, upgrading to version 9.2.11 or 10.0.6 is strongly recommended.
Affected Version(s)
Apache Traffic Server 10.0.0 <= 10.0.5
Apache Traffic Server 9.0.0 <= 9.2.10