CVE-2026-65100: CWE-696 Incorrect Behavior Order in Apache Software Foundation Apache Traffic Server
Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the connection. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
AI Analysis
Technical Summary
CVE-2026-65100 is a vulnerability in Apache Traffic Server where the HTTP/2 HPACK dynamic table is updated prematurely before confirming that the header block encoding succeeded. If encoding fails, this results in the encoder and peer decoder becoming unsynchronized, which corrupts subsequent header blocks on the affected HTTP/2 connection. This affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Upgrading to versions 9.2.15 or 10.1.4 resolves the issue.
Potential Impact
The vulnerability can cause corruption of HTTP/2 header blocks on a connection due to encoder and decoder state desynchronization. This may lead to degraded service or denial of service conditions affecting availability. The CVSS score of 4.8 (medium severity) reflects limited impact on confidentiality and integrity, with some impact on availability.
Mitigation Recommendations
Users should upgrade Apache Traffic Server to version 9.2.15 or 10.1.4 or later, where this issue is fixed. No other mitigations are specified. Patch status is confirmed by the vendor advisory recommending these versions.
CVE-2026-65100: CWE-696 Incorrect Behavior Order in Apache Software Foundation Apache Traffic Server
Description
Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so an encode failure leaves the encoder out of sync with the peer decoder and corrupts subsequent header blocks on the connection. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.9, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3. Users are recommended to upgrade to version 9.2.15 or 10.1.4, which fix the issue.
CVSS v3.1
Score 4.8medium
Affected software
Apache Software Foundation
Apache Traffic Server
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-65100 is a vulnerability in Apache Traffic Server where the HTTP/2 HPACK dynamic table is updated prematurely before confirming that the header block encoding succeeded. If encoding fails, this results in the encoder and peer decoder becoming unsynchronized, which corrupts subsequent header blocks on the affected HTTP/2 connection. This affects Apache Traffic Server versions 8.0.0 through 8.1.9, 9.0.0 through 9.2.14, and 10.0.0 through 10.1.3. Upgrading to versions 9.2.15 or 10.1.4 resolves the issue.
Potential Impact
The vulnerability can cause corruption of HTTP/2 header blocks on a connection due to encoder and decoder state desynchronization. This may lead to degraded service or denial of service conditions affecting availability. The CVSS score of 4.8 (medium severity) reflects limited impact on confidentiality and integrity, with some impact on availability.
Mitigation Recommendations
Users should upgrade Apache Traffic Server to version 9.2.15 or 10.1.4 or later, where this issue is fixed. No other mitigations are specified. Patch status is confirmed by the vendor advisory recommending these versions.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-07-21T17:10:18.202Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a69c9f59c2644c7f8487ef3
Added to database: 07/29/2026, 09:37:57 UTC
Last enriched: 08/06/2026, 19:42:51 UTC
Last updated: 09/11/2026, 22:06:34 UTC
Views: 75
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.