Excessive Memory Consumption in ESI Plugin for Apache Traffic Server
CVE-2025-49763

7.5HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
19 June 2025

Badges

đź“° News Worthy

What is CVE-2025-49763?

The ESI plugin for Apache Traffic Server presents a vulnerability due to the absence of a limit on the maximum inclusion depth. This oversight can lead to excessive memory consumption when malicious instructions are inserted into the system. Users of Apache Traffic Server are encouraged to leverage the newly introduced setting (--max-inclusion-depth) to impose this limit. The issue has been identified across various versions of Apache Traffic Server, including those from versions 9.0.0 to 9.2.10 and 10.0.0 to 10.0.5. To mitigate this risk, upgrading to version 9.2.11 or 10.0.6 is strongly recommended.

Affected Version(s)

Apache Traffic Server 10.0.0 <= 10.0.5

Apache Traffic Server 9.0.0 <= 9.2.10

News Articles

Apache Traffic Server CVE-2025-49763 Memory Exhaustion Risk

CVE-2025-49763 in Apache Traffic Server’s ESI plugin enables DoS attacks via memory exhaustion. Upgrade ATS and configure ACL settings to mitigate risks.

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • đź“°

    First article discovered by The Cyber Express

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yohann Sillam
.