VendorsApachetraffic_controlall versions
Vulnerabilities

Apache Software Foundation Traffic Control

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2024-45387
Apache Traffic Control: SQL Injection in Traffic Ops endpoint PUT deliveryservice_request_comments
Published 2024-12-23 · Analyzed
9.9EPSS 0.424
CVE-2021-43350
LDAP filter injection vulnerability in Traffic Ops
Published 2021-11-11 · Modified
9.8EPSS 0.048
CVE-2019-12405
Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user that can be authenticated via LDAP, it is possible to improperly authenticate as that user without that user's correct password.
Published 2019-09-09 · Modified
9.8EPSS 0.035
CVE-2017-7670
The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TCP connections made on the configured DNS port will remain in the ESTABLISHED state until the client explicitly closes the connection or Traffic Router is restarted. If connections remain in the ESTABLISHED state indefinitely and accumulate in number to match the size of the thread pool dedicated to processing DNS requests, the thread pool becomes exhausted. Once the thread pool is exhausted, Traffic Router is unable to service any DNS request, regardless of transport protocol.
Published 2017-07-10 · Modified
7.5EPSS 0.047
CVE-2022-23206
Server-Side Request Forgery in Traffic Ops endpoint POST /user/login/oauth
Published 2022-02-06 · Modified
7.5EPSS 0.020
CVE-2025-61581
Apache Traffic Control: ReDoS issue in Traffic Router configuration
Published 2025-10-16 · Modified
7.5EPSS 0.007
CVE-2020-17522
When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that allow bad actors to push arbitrary content into and remove arbitrary content from CDN cache servers. Additionally, these permissions are potentially extended to IP addresses outside the desired range, resulting in them being granted to clients possibly outside the CDN arcitechture.
Published 2021-01-26 · Modified
5.8EPSS 0.039
CVE-2021-42009
Apache Traffic Control Traffic Ops Email Injection Vulnerability
Published 2021-10-12 · Modified
4.3EPSS 0.028