Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 445
Alerts This Week
Warning Icon 1 445

Fedora 44 Trafficserver DoS CVE-2026-59173 Update 2026-bb8dc1e5b6

fedora
Calendar Grey July 26, 2026
Scroller Fedora
This advisory addresses a DoS issue in HTTP/2 flow-control for Apache Traffic Server on Fedora 44 and includes critical updates.
Fedora 44 has released Traffic Server 10.1.3, enhancing performance and resolving security vulnerabilities, including a DoS issue in HTTP/2 and various other bug fixes and improvem...

Summary

Traffic Server is a high-performance building block for cloud services.

It's more than just a caching proxy server; it also has support for

plugins to build large scale web applications. Key features:

Caching - Improve your response time, while reducing server load and

bandwidth needs by caching and reusing frequently-requested web pages,

images, and web service calls.

Proxying - Easily add keep-alive, filter or anonymize content

requests, or add load balancing by adding a proxy layer.

Fast - Scales well on modern SMP hardware, handling 10s of thousands

of requests per second.

Extensible - APIs to write your own plug-ins to do anything from

modifying HTTP headers to handling ESI requests to writing your own

cache algorithm.

Proven - Handling over 400TB a day at Yahoo! both as forward and

reverse proxies, Apache Traffic Server is battle hardened.

Update Information:

Resolves CVE-2026-59173 - DoS vulnerability in HTTP/2 via stalled flow-control Additional Changes with Apache Traffic Server 9.2.14 #12910 - Fix connection-level window mismatch causing 408/504 timeouts #13266 - Add Claude Code project guide for the 9.2.x branch #13267 - [9.2.x] Backport format scripts fixes #13377 - 9.2.x: http2: Track scheduled events Additional Changes with Apache Traffic Server 10.1.3 #12192 - Return a 400 on chunk parse errors #12733 - Fix retry logic for TSHttpTxnServerAddrSet (issue #12611) #12854 - Fix LoadedPlugins::remove crash during static destruction #12855 - Fix header_rewrite run-plugin relative path resolution #12857 - Fix autest compatibility with Fedora 43 / Python 3.14 #12943 - Address incompatibility with BoringSSL #12959 - Fix crash in HttpSM::tunnel_handler on unhandled VC events #12972 - Fix cache retry assert on ServerAddrSet #12990 - Update to Proxy Verifier v3.0.0 #13008 - cmake: limit GENERAL_NAM...

Change Log

* Wed Jul 15 2026 Jered Floyd - 10.1.3-1 - Update to upstream 10.1.3 * Fri Jun 12 2026 Yaakov Selkowitz - 10.1.2-2 - Rebuilt for openssl 4.0

References


[ 1 ] Bug #2501029 - trafficserver-10.1.3 is available https://bugzilla.redhat.com/show_bug.cgi?id=2501029

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-bb8dc1e5b6' at the command line. For more information, refer to the dnf documentation available at http://dnf.readthedocs.io/en/latest/command_ref.html#upgrade-command-label

Severity
important
Lowest
Low
Medium
High
Critical

Name: trafficserver
Product: Fedora 44
Version: 10.1.3
Release: 1.fc44
Summary: Fast, scalable and extensible HTTP/1.1 and HTTP/2 caching proxy server

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.