HTTP/2 Framing Vulnerability in Apache Traffic Server by Apache
CVE-2026-58151
8.7HIGH
What is CVE-2026-58151?
Apache Traffic Server is vulnerable to a resource exhaustion issue caused by maliciously constructed HTTP/2 framing and flow control. This flaw enables attackers to intentionally crash the server or deplete its resources, leading to service disruption. Users are advised to upgrade to version 9.2.15 or 10.1.4, which contain fixes for this vulnerability.
Affected Version(s)
Apache Traffic Server 8.0.0 <= 8.1.9
Apache Traffic Server 9.0.0 <= 9.2.14
Apache Traffic Server 10.0.0 <= 10.1.3