What is CVE-2026-65100?
CVE-2026-65100: In Apache Traffic Server, the HTTP/2 HPACK dynamic table is updated before confirming the header block encoding, so an encode failure desynchronizes the encoder from the peer decoder, corrupting subsequent header blocks on the connection. This issue affects Apache Traffic Server versions starting from 8.0, and applying the relevant patch or reviewing HTTP/2 configuration is advised.
Azərbaycanca: CVE-2026-65100: Apache Traffic Server-də HTTP/2 HPACK dynamic table-in header təsdiqlənməmişdən əvvəl yenilənməsi səbəbindən encode uğursuzluğu baş verdikdə, encoder peer decoder ilə sinxronizasiyanı itirir və əlaqədəki sonrakı header block-lar korlanır. Bu, Apache Traffic Server-in 8.0-dan başlayan versiyalarına təsir edir. Müvafiq yamaq tətbiq olunana qədər serveri yeniləmək və ya HTTP/2 konfiqurasiyasını nəzərdən keçirmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: Apache
FAQ2
How does the CVE-2026-65100 vulnerability occur in Apache Traffic Server?
Because the HTTP/2 HPACK dynamic table is updated before confirming the header block encoding, an encode failure desynchronizes the encoder from the peer decoder, corrupting subsequent header blocks on the connection.
Which Apache Traffic Server versions are affected by this vulnerability?
This issue affects Apache Traffic Server versions starting from 8.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.