Severity: low 

Affected versions:

- Apache Traffic Control: all versions

Description:

** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity 
vulnerability in Apache Traffic Control.

This issue affects Apache Traffic Control: all versions.

People with access to the management interface of the Traffic Router component 
could specify malicious patterns and cause unavailability.

As this project is retired, we do not plan to release a version that fixes this 
issue. Users are recommended to find an alternative or restrict access to the 
instance to trusted users.

NOTE: This vulnerability only affects products that are no longer supported by 
the maintainer.

Credit:

Chris Lemmons (finder)

References:

https://trafficcontrol.apache.org/
https://www.cve.org/CVERecord?id=CVE-2025-61581

Reply via email to