CVE-2026-65100

NameCVE-2026-65100
DescriptionApache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the connection. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
trafficserver (PTS)bullseye8.1.10+ds-1~deb11u1vulnerable
bullseye (security)8.1.11+ds-0+deb11u2vulnerable
bookworm, bookworm (security)9.2.5+ds-0+deb12u4vulnerable
sid9.2.5+ds-1vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
trafficserversource(unstable)(unfixed)

Notes

https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d

Search for package or bug name: Reporting problems