← Vulnerability feed

Vulnerability record · CVE-2017-7670 · published 10 July 2017

CVE-2017-7670: Apache traffic control uncontrolled resource consumption vulnerability

Apache · Traffic Control

The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TCP connections made on the configured DNS port will remain in the ESTABLISHED state until the client explicitly closes the connection or Traffic Router is restarted. If connections remain in the ESTABLISHED state indefinitely and accumulate in number to match the size of the thread pool dedicated to processing DNS requests, the thread pool becomes exhausted. Once the thread pool is exhausted, Traffic Router is unable to service any DNS request, regardless of transport protocol.

7.5 CVSS 3.0 High EPSS 4.7% · top 8.6% CWE-400 · Uncontrolled resource consumption
7.5CVSS 3.0 base score, v2 5.0
4.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TCP connections made on the configured DNS port will remain in the ESTABLISHED state until the client explicitly closes the connection or Traffic Router is restarted. If connections remain in the ESTABLISHED state indefinitely and accumulate in number to match the size of the thread pool dedicated to processing DNS requests, the thread pool becomes exhausted. Once the thread pool is exhausted, Traffic Router is unable to service any DNS request, regardless of transport protocol.

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2017-7670 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-43350Apache traffic control ldap injection vulnerabilityAn unauthenticated Apache Traffic Control Traffic Ops user can send a request with a specially-crafted username to the POST /login endpoint of any AP…EPSS 4.8%9.8CVE-2019-12405Apache traffic control improper authentication vulnerabilityImproper authentication is possible in Apache Traffic Control versions 3.0.0 and 3.0.1 if LDAP is enabled for login in the Traffic Ops API component.…EPSS 3.5%8.8CVE-2024-45387Apache traffic control sql injection vulnerabilityAn SQL injection vulnerability in Traffic Ops in Apache Traffic Control <= 8.0.1, >= 8.0.0 allows a privileged user with role "admin", "federation", …EPSS 42%7.5CVE-2025-61581Apache traffic control inefficient regular expression (redos) vulnerability** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This issue affects Apache Traffic …EPSS 0.74%7.5CVE-2022-23206Apache traffic control server-side request forgery (ssrf) vulnerabilityIn Apache Traffic Control Traffic Ops prior to 6.1.0 or 5.1.6, an unprivileged user who can reach Traffic Ops over HTTPS can send a specially-crafted…EPSS 2.0%5.8CVE-2020-17522Apache traffic control incorrect permission assignment vulnerabilityWhen ORT (now via atstccfg) generates ip_allow.config files in Apache Traffic Control 3.0.0 to 3.1.0 and 4.0.0 to 4.1.0, those files include permissi…EPSS 3.9%4.3CVE-2021-42009Apache traffic control improper input validation vulnerabilityAn authenticated Apache Traffic Control Traffic Ops user with Portal-level privileges can send a request with a specially-crafted email subject to th…EPSS 2.8%7.5CVE-2026-28318SolarWinds Serv-U unauthenticated POST request denial of serviceSolarWinds Serv-U crashes when it receives a specially crafted POST request using Content-Encoding: deflate, and the crash occurs without authenticat…KEVEPSS 1.9%analysed

Source: NIST National Vulnerability Database (record CVE-2017-7670), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.