Improper control of a resource through its lifetime in Apache Traffic Server - CVE-2026-65100
Published: August 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to corrupt subsequent HTTP/2 header processing.
The vulnerability exists due to improper state management in the HTTP/2 HPACK encoder when handling a failed header encode. A remote attacker can trigger an encode failure to corrupt subsequent HTTP/2 header processing.
The issue leaves the encoder out of sync with the peer decoder on the connection.
Affected software
Fedora
trafficserver
How to mitigate CVE-2026-65100
trafficserver - addressed in versions 9.2.15-1.el8, 9.2.15-1.el9, 10.1.4-1.fc43, 10.1.4-1.fc44