Excessive Memory Consumption in ESI Plugin for Apache Traffic Server
CVE-2025-49763

7.5HIGH

Key Information:

Vendor

Apache

Vendor
CVE Published:
19 June 2025

What is CVE-2025-49763?

The ESI plugin for Apache Traffic Server presents a vulnerability due to the absence of a limit on the maximum inclusion depth. This oversight can lead to excessive memory consumption when malicious instructions are inserted into the system. Users of Apache Traffic Server are encouraged to leverage the newly introduced setting (--max-inclusion-depth) to impose this limit. The issue has been identified across various versions of Apache Traffic Server, including those from versions 9.0.0 to 9.2.10 and 10.0.0 to 10.0.5. To mitigate this risk, upgrading to version 9.2.11 or 10.0.6 is strongly recommended.

Affected Version(s)

Apache Traffic Server 10.0.0 <= 10.0.5

Apache Traffic Server 9.0.0 <= 9.2.10

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yohann Sillam
.