CVE-2026-59173
EPSS 0.22%
Description
Uncontrolled Resource Consumption vulnerability in Apache Traffic Server. This issue affects Apache Traffic Server: from 9.0.0 through 9.1.13, from 10.0.0 through 10.1.2. Users are recommended to upgrade to version 9.1.14 or 10.1.3, which fixes the issue.
How to fix CVE-2026-59173
No fixed version has been published yet. Mitigate by removing the affected package or applying upstream guidance from the references below.
- Debian/trafficserver—no fix listed
Is CVE-2026-59173 being exploited?
Low — EPSS is 0.2%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0