Linuxsecurity Critical DoS Vulnerability in Apache Traffic Server Fixed in Fedora 43 and 44
Article Content
- •CVE-2026-59173 is a critical DoS vulnerability in Apache Traffic Server affecting Fedora 43 and 44.
- •The vulnerability allows for DoS attacks via stalled flow-control in HTTP/2, impacting service availability.
- •Administrators are advised to update their systems promptly to mitigate risks associated with this flaw.
Fedora has released updates to address a critical denial-of-service (DoS) vulnerability, CVE-2026-59173, affecting Apache Traffic Server. The flaw, which allows for DoS attacks via stalled flow-control in HTTP/2, was published on July 18, 2026. Affected systems include Fedora 43 and 44, with updates available for both versions. The vulnerability could lead to significant service disruptions for users relying on Traffic Server for cloud services. Administrators are urged to audit Linux privileges to limit potential compromises. The updates also include various bug fixes and enhancements to improve performance and stability. Users can apply the updates using the 'dnf' package manager.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (4)
Following this threat?
Track Fedora and CVE-2026-59173 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure On September 10, 2026, GitLab released patches for critical vulnerabilities CVE-2026-85706 and CVE-2026-87719. CVE-2026-85706, a path traversal flaw, allows unauthenticated users to read arbitrary files from GitLab servers, while CVE-2026-87719 enables credential theft via insecure deserialization. Both…