Apache Software FoundationCVE-2026-65100
Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming...
Medium6.3CVE-2026-65100 · Published Jul 29, 2026 · updated Oct 1, 2026
Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the connection. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apache Traffic Server Product | >= 8.0.0, <= 8.1.11 | No fix yet |
| >= 9.0.0, <= 9.2.14 | No fix yet | |
| >= 10.0.0, <= 10.1.3 | No fix yet |
Details and references
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-696
More Apache Software Foundation advisories
All Apache Software Foundation| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 29 | Apache Traffic Server: out-of-bounds write | High8.4 | No fix yet |
| Jul 29 | Apache Traffic Server: server-side request forgery | High8.2 | No fix yet |
| Jul 29 | Apache Traffic Server: stack buffer overflow | High8.2 | No fix yet |
| Jul 29 | Apache Traffic Server: resource exhaustion | High8.2 | No fix yet |
| Jul 29 | Apache Traffic Server: improper input validation | High8.2 | No fix yet |
| Jul 29 | Apache Traffic Server: out-of-bounds write | High8.3 | No fix yet |