#VU118829 Inefficient regular expression complexity in Apache Traffic Control - CVE-2025-61581
Published: November 28, 2025
Apache Traffic Control
Apache Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient input validation when processing untrusted input with a regular expressions. A remote attacker can pass specially crafted data to the application and perform regular expression denial of service (ReDos) attack.
Remediation
Note, the product is no longer supported by the vendor. It is recommended to migrate to another solution.