GHSA-f2wr-c4c4-xjg7

    Dashboard / Vulnerabilities / GHSA-f2wr-c4c4-xjg7

    GHSA-f2wr-c4c4-xjg7

    Published: 13 May 2022Last Modified: 9 Jul 2025
    Aliases:

    Summary: Apache Traffic Control vulnerable to Slowloris-style Denial of Service attack

    Details: The Traffic Router component of the incubating Apache Traffic Control project is vulnerable to a Slowloris style Denial of Service attack. TCP connections made on the configured DNS port will remain in the `ESTABLISHED` state until the client explicitly closes the connection or Traffic Router is restarted. If connections remain in the `ESTABLISHED` state indefinitely and accumulate in number to match the size of the thread pool dedicated to processing DNS requests, the thread pool becomes exhausted. Once the thread pool is exhausted, Traffic Router is unable to service any DNS request, regardless of transport protocol.

    Affected packages

    Package

    Name: github.com/apache/trafficcontrol

    Purl: pkg:golang/github.com/apache/trafficcontrol

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 1.1.4
    Fixed -1.8.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High