A critical vulnerability CVE-2025-49763 has been found in Apache Traffic Server, which can be exploited to cause denial-of-service attacks by exhausting server memory through the Edge Side Includes plugin. Organizations using affected versions are urged to upgrade and adjust their configurations to prevent potential service disruptions. #ApacheTrafficServer #CVE202549763
Keypoints
- A new security flaw affects Apache Traffic Server versions 9.0.0 to 9.2.10 and 10.0.0 to 10.0.5.
- The vulnerability is related to the ESI pluginβs processing of nested inclusion requests, leading to memory exhaustion.
- An associated ACL issue impacts the handling of proxy protocol client IP addresses, increasing the attack surface.
- Microsoft recommends updating to ATS 9.2.11 or 10.0.6 and configuring new security settings to mitigate risks.
- Failure to address these vulnerabilities may result in server outages and significant operational impact.
Read More: https://thecyberexpress.com/apache-traffic-server-cve-2025-49763/