Traffic Control
Vendor:
First CVE: Jul 10, 2017 · Active for 9 years
8
Total CVEs
More Total CVEs than 85% of tracked products
1.3
Avg CVEs / Year
Higher CVE frequency than 55% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Traffic Control over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 10, 2017
9 years ago
Most Recent CVE
Oct 16, 2025
281 days ago
CVE Severity & Scoring
Traffic Control8 CVEs
25%
50%
25%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network8 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (25.0%)
High0 (0.0%)
None6 (75.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-45387HIGH An SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", "operations", "portal", or "ste | Dec 23, 2024 | 8.8 | 45 | NO | NO |
CVE-2021-43350CRITICAL An unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any API version to inject unsanitized | Nov 11, 2021 | 9.8 | 31 | NO | NO |
CVE-2019-12405CRITICAL Improper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component. Given a username for a user th | Sep 9, 2019 | 9.8 | 31 | NO | NO |
CVE-2025-61581HIGH ** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control.
This issue affects Apache Traffic Control: all versions.
People | Oct 16, 2025 | 7.5 | 26 | NO | NO |
CVE-2022-23206HIGH In Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted POST request to /user/login/oa | Feb 6, 2022 | 7.5 | 26 | NO | NO |
CVE-2017-7670HIGH The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TCP connections made on the configured DN | Jul 10, 2017 | 7.5 | 26 | NO | NO |
CVE-2021-42009MEDIUM An authenticated Apache Traffic Control Traffic Ops user with Portal-level privileges can send a request with a specially-crafted email subject to the /deliveryservices/request Tra | Oct 12, 2021 | 4.3 | 19 | NO | NO |
CVE-2020-17522MEDIUM When ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissions that allow bad actors to pu | Jan 26, 2021 | 5.8 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Traffic Control
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 6.0.1 | 1 | 9.8 | 4.4% | 0 | 0 |
| 5.1.4 | 1 | 9.8 | 4.4% | 0 | 0 |
| 3.0.1 | 1 | 9.8 | 3.5% | 0 | 0 |
| 3.0.0 | 1 | 9.8 | 3.5% | 0 | 0 |
| 2.0.0 | 1 | 7.5 | 4.8% | 0 | 0 |
| 1.8.1 | 1 | 7.5 | 4.8% | 0 | 0 |