Memory Exhaustion Vulnerability in Apache Traffic Server Affecting Multiple Versions
CVE-2026-65324
8.2HIGH
What is CVE-2026-65324?
A memory exhaustion vulnerability in Apache Traffic Server allows slow clients to exhaust server memory by dropping the per-stream buffer cap during the dechunking of HTTP/2 or HTTP/3 responses. This issue affects several versions of the software and can lead to significant service disruption. To mitigate the risk, users should upgrade to the fixed versions: 9.2.15 or 10.1.4.
Affected Version(s)
Apache Traffic Server 8.0.0 <= 8.1.9
Apache Traffic Server 9.0.0 <= 9.2.14
Apache Traffic Server 10.0.0 <= 10.1.3