CVE-2026-59173
published 2026-07-18CVE-2026-59173: Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.51%
40.2th percentile
Uncontrolled Resource Consumption vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2.
Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache_software_foundation | apache_traffic_server | 10.0.0 – 10.1.2 | — |
| apache_software_foundation | apache_traffic_server | 9.0.0 – 9.2.13 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Uncontrolled Resource Consumption vulnerability in Apache Traffic Server.
ghsa_unreviewed·2026-07-18
CVE-2026-59173 CWE-400 Uncontrolled Resource Consumption vulnerability in Apache Traffic Server.
Uncontrolled Resource Consumption vulnerability in Apache Traffic Server.
This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2.
Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue.
VulDB
Apache Traffic Server up to 9.1.13/10.1.2 resource consumption
vuldb·2026-07-18
CVE-2026-59173 [LOW] Apache Traffic Server up to 9.1.13/10.1.2 resource consumption
A vulnerability identified as problematic has been detected in Apache Traffic Server up to 9.1.13/10.1.2. This vulnerability affects unknown code. This manipulation causes resource consumption.
This vulnerability appears as CVE-2026-59173. The attack may be initiated remotely. There is no available exploit.
No detection rules found.
No public exploits indexed.
2026-07-18
Published