Inefficient regular expression complexity in Apache Traffic Control - CVE-2025-61581
Published: November 28, 2025
Apache Traffic Control
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation when processing untrusted input with a regular expressions. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.
How to mitigate CVE-2025-61581
Note, the product is no longer supported by the vendor. It is recommended to migrate to another solution.