Critical DoS Vulnerability in Apache Traffic Server Fixed in Fedora 43 and 44

Critical DoS Vulnerability in Apache Traffic Server Fixed in Fedora 43 and 44

First seen 27 Jul 2026, 08:31 UTC Linuxsecurity 95% similarity 70.5

Article Content

Browse articles
ThreatCluster

Fedora has released updates to address a critical denial-of-service (DoS) vulnerability, CVE-2026-59173, affecting Apache Traffic Server. The flaw, which allows for DoS attacks via stalled flow-control in HTTP/2, was published on July 18, 2026. Affected systems include Fedora 43 and 44, with updates available for both versions. The vulnerability could lead to significant service disruptions for users relying on Traffic Server for cloud services. Administrators are urged to audit Linux privileges to limit potential compromises. The updates also include various bug fixes and enhancements to improve performance and stability. Users can apply the updates using the 'dnf' package manager.

Key Points: • CVE-2026-59173 is a critical DoS vulnerability in Apache Traffic Server affecting Fedora 43 and 44. • The vulnerability allows for DoS attacks via stalled flow-control in HTTP/2, impacting service availability. • Administrators are advised to update their systems promptly to mitigate risks associated with this flaw.

ThreatCluster AI

Timeline

2026-07-18
CVE-2026-59173 published
A critical DoS vulnerability in Apache Traffic Server was disclosed, affecting multiple Fedora versions.
Linuxsecurity
2026-07-27
Fedora updates released
Fedora released updates for Traffic Server to address CVE-2026-59173, urging users to upgrade.
Linuxsecurity

Community

Browse all →