CVE-2025-49763
published 2025-06-19CVE-2025-49763: ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. Users can…
PriorityP343high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.63%
46.6th percentile
ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted.
Users can use a new setting for the plugin (--max-inclusion-depth) to limit it.
This issue affects Apache Traffic Server: from 10.0.0 through 10.0.5, from 9.0.0 through 9.2.10.
Users are recommended to upgrade to version 9.2.11 or 10.0.6, which fixes the issue.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | traffic_server | >= 10.0.0 < 10.0.6 | 10.0.6 |
| apache | traffic_server | >= 9.0.0 < 9.2.11 | 9.2.11 |
| apache_software_foundation | apache_traffic_server | 10.0.0 – 10.0.5 | — |
| apache_software_foundation | apache_traffic_server | 9.0.0 – 9.2.10 | — |
| debian | trafficserver | < trafficserver 9.2.5+ds-0+deb12u3 (bookworm) | trafficserver 9.2.5+ds-0+deb12u3 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-jrg5-jw7r-rxg9: ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted
ghsa_unreviewed·2025-06-19
CVE-2025-49763 [HIGH] CWE-400 GHSA-jrg5-jw7r-rxg9: ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted
ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted.
Users can use a new setting for the plugin (--max-inclusion-depth) to limit it.
This issue affects Apache Traffic Server: from 10.0.0 through 10.0.5, from 9.0.0 through 9.2.10.
Users are recommended to upgrade to version 9.2.11 or 10.0.6, which fixes the issue.
OSV
CVE-2025-49763: ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted
osv·2025-06-19·CVSS 7.5
CVE-2025-49763 [HIGH] CVE-2025-49763: ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted
ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. Users can use a new setting for the plugin (--max-inclusion-depth) to limit it. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.5, from 9.0.0 through 9.2.10. Users are recommended to upgrade to version 9.2.11 or 10.0.6, which fixes the issue.
Red Hat
trafficserver: Traffic Server ESI Inclusion Depth Vulnerability
vendor_redhat·2025-06-19·CVSS 7.5
CVE-2025-49763 [HIGH] CWE-400 trafficserver: Traffic Server ESI Inclusion Depth Vulnerability
trafficserver: Traffic Server ESI Inclusion Depth Vulnerability
ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted.
Users can use a new setting for the plugin (--max-inclusion-depth) to limit it.
This issue affects Apache Traffic Server: from 10.0.0 through 10.0.5, from 9.0.0 through 9.2.10.
Users are recommended to upgrade to version 9.2.11 or 10.0.6, which fixes the issue.
A flaw was found in trafficserver. The Edge Side Includes (ESI) plugin lacks a limit on maximum inclusion depth, allowing a remote attacker to trigger excessive memory consumption by inserting malicious instructions. This condition occurs due to the plugin's inability to restrict the nesting of ESI includes, potentially l
Debian
CVE-2025-49763: trafficserver - ESI plugin does not have the limit for maximum inclusion depth, and that allows ...
vendor_debian·2025·CVSS 7.5
CVE-2025-49763 [HIGH] CVE-2025-49763: trafficserver - ESI plugin does not have the limit for maximum inclusion depth, and that allows ...
ESI plugin does not have the limit for maximum inclusion depth, and that allows excessive memory consumption if malicious instructions are inserted. Users can use a new setting for the plugin (--max-inclusion-depth) to limit it. This issue affects Apache Traffic Server: from 10.0.0 through 10.0.5, from 9.0.0 through 9.2.10. Users are recommended to upgrade to version 9.2.11 or 10.0.6, which fixes the issue.
Scope: local
bookworm: resolved (fixed in 9.2.5+ds-0+deb12u3)
bullseye: open
sid: open
No detection rules found.
No public exploits indexed.
Wiz
CVE-2025-58136 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-58136 [HIGH] CVE-2025-58136 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-58136 :
Apache Traffic Server vulnerability analysis and mitigation
A bug in POST request handling causes a crash under a certain condition.
This issue affects Apache Traffic Server: from 10.0.0 through 10.1.1, from 9.0.0 through 9.2.12.
Users are recommended to upgrade to version 10.1.2 or 9.2.13, which fix the issue.
A workaround for older versions is to set proxy.config.http.request_buffer_enabled to 0 (the default value is 0).
Source : NVD
## 7.5
Score
Published April 2, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Apache Traffic Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 40
Exploitation Probability (EPSS) 0.2
Affected packages a
Wiz
CVE-2025-65114 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-65114 [HIGH] CVE-2025-65114 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-65114 :
Apache Traffic Server vulnerability analysis and mitigation
Apache Traffic Server allows request smuggling if chunked messages are malformed.
This issue affects Apache Traffic Server: from 9.0.0 through 9.2.12, from 10.0.0 through 10.1.1.
Users are recommended to upgrade to version 9.2.13 or 10.1.2, which fix the issue.
Source : NVD
## 7.5
Score
Published April 2, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Apache Traffic Server
Linux Debian
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 37.2
Exploitation Probability (EPSS) 0.2
Affected packages and libraries
trafficserver
cpe:2.3:a:apache:traffic_server
Sources
Debian 11 Severity HIGH No Fix Ad
2025-06-19
Published