Excessive Memory Consumption in ESI Plugin for Apache Traffic Server
CVE-2025-49763
What is CVE-2025-49763?
The ESI plugin for Apache Traffic Server presents a vulnerability due to the absence of a limit on the maximum inclusion depth. This oversight can lead to excessive memory consumption when malicious instructions are inserted into the system. Users of Apache Traffic Server are encouraged to leverage the newly introduced setting (--max-inclusion-depth) to impose this limit. The issue has been identified across various versions of Apache Traffic Server, including those from versions 9.0.0 to 9.2.10 and 10.0.0 to 10.0.5. To mitigate this risk, upgrading to version 9.2.11 or 10.0.6 is strongly recommended.
Affected Version(s)
Apache Traffic Server 10.0.0 <= 10.0.5
Apache Traffic Server 9.0.0 <= 9.2.10
News Articles

Apache Traffic Server CVE-2025-49763 Memory Exhaustion Risk
CVE-2025-49763 in Apache Traffic Server’s ESI plugin enables DoS attacks via memory exhaustion. Upgrade ATS and configure ACL settings to mitigate risks.
References
CVSS V3.1
Timeline
- đź“°
First article discovered by The Cyber Express
Vulnerability published
Vulnerability Reserved