CVE-2025-61581 Details
Description
** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This issue affects Apache Traffic Control: all versions. People with access to the management interface of the Traffic Router component could specify malicious patterns and cause unavailability. As this project is retired, we do not plan to release a version that fixes this issue. Users are recommended to find an alternative or restrict access to the instance to trusted users. NOTE: This vulnerability only affects products that are no longer supported by the maintainer.
A denial-of-service vulnerability has been identified in Apache Traffic Control's Traffic Router component, all versions. This issue arises from inefficient regular expression processing, allowing users with access to the management interface to introduce malicious patterns that can lead to unavailability. As Apache Traffic Control is a retired project, no fix will be released. Users are advised to seek alternatives or limit access to trusted individuals.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Oct 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2025/10/16/3 | CVE | |
| https://lists.apache.org/thread/mx2jxgnlop2f4vbqnvmrldh4pqmobxvp | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1333 | Inefficient Regular Expression Complexity | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache traffic control | <= 8.0.2 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Nov 4, 2025 | CVE Modified | CVE |
| Oct 20, 2025 | Initial Analysis | [email protected] |
| Oct 17, 2025 | CVE Modified | CISA-ADP |
| Oct 16, 2025 | New CVE Received | [email protected] |