CVE-2025-49763: Apache Traffic Server Vulnerability Enables Memory Exhaustion Attacks

CVE-2025-49763: Apache Traffic Server Vulnerability Enables Memory Exhaustion Attacks

A critical vulnerability CVE-2025-49763 has been found in Apache Traffic Server, which can be exploited to cause denial-of-service attacks by exhausting server memory through the Edge Side Includes plugin. Organizations using affected versions are urged to upgrade and adjust their configurations to prevent potential service disruptions. #ApacheTrafficServer #CVE202549763

Keypoints

  • A new security flaw affects Apache Traffic Server versions 9.0.0 to 9.2.10 and 10.0.0 to 10.0.5.
  • The vulnerability is related to the ESI plugin’s processing of nested inclusion requests, leading to memory exhaustion.
  • An associated ACL issue impacts the handling of proxy protocol client IP addresses, increasing the attack surface.
  • Microsoft recommends updating to ATS 9.2.11 or 10.0.6 and configuring new security settings to mitigate risks.
  • Failure to address these vulnerabilities may result in server outages and significant operational impact.

Read More: https://thecyberexpress.com/apache-traffic-server-cve-2025-49763/