{"package":"github.com/apache/trafficcontrol","ecosystem":"go","latest_version":"v7.0.1+incompatible","description":"Apache Traffic Control is an Open Source implementation of a Content Delivery Network","license":"","license_risk":"unknown","commercial_use_notes":"No license declared in registry metadata — verify manually before commercial use.","homepage":"https://pkg.go.dev/github.com/apache/trafficcontrol","repository":"https://github.com/apache/trafficcontrol","downloads_weekly":1157,"health":{"score":35,"risk":"critical","breakdown":{"maintenance":0,"popularity":6,"security":20,"maturity":9,"community":0},"deprecated":false,"max_score":100},"vulnerabilities":{"count":2,"critical":0,"high":1,"medium":0,"low":1,"details":[{"vuln_id":"CVE-2017-7670","severity":"high","summary":"Apache Traffic Control vulnerable to Slowloris-style Denial of Service attack","affected_versions":">=1.1.4,<1.8.1|>=2.0.0-RC0,<2.0.0|>=2.1.0-RC0,<2.1.0-RC1|<0.0.0-20170531185407-738c10fa1b58|>=0.0.0,<1.1.4-0.20170531185407-738c10fa1b58|=2.1.0-RC0","fixed_version":"1.1.4-0.20170531185407-738c10fa1b58","source":"osv","published_at":"2022-05-13T01:09:17Z","in_kev":false,"epss_prob":0.01728,"epss_percentile":0.82513,"threat_tier":"theoretical"},{"vuln_id":"CVE-2025-61581","severity":"unknown","summary":"Apache Traffic Control has an Inefficient Regular Expression Complexity vulnerability in github.com/apache/trafficcontrol","affected_versions":null,"fixed_version":null,"source":"osv","published_at":"2025-10-30T15:02:33Z","in_kev":false,"epss_prob":0.00316,"epss_percentile":0.54701,"threat_tier":"theoretical"}],"actively_exploited_count":0,"likely_exploited_count":0},"versions":{"latest":"v7.0.1+incompatible","total_count":20,"recent":["v5.1.2+incompatible","v5.1.6+incompatible","v6.0.2+incompatible","v6.1.0+incompatible","v5.1.3+incompatible","v7.0.0+incompatible","v7.0.0-rc0+incompatible","v7.0.1-rc0+incompatible","v6.0.1+incompatible","v1.1.3","v8.0.0-rc0+incompatible","v7.0.0-rc2+incompatible","v7.0.0-rc1+incompatible","v5.0.0+incompatible","v5.1.4+incompatible","v7.0.1+incompatible","v5.1.1+incompatible","v1.1.5-retractions","v6.0.0+incompatible","v5.1.0+incompatible"]},"metadata":{"deprecated":false,"deprecated_message":null,"maintainers_count":191,"first_published":null,"last_published":"2022-08-25T12:31:14Z","dependencies_count":0,"dependencies":[]},"bundle":null,"typescript":null,"known_issues":{"bugs_count":0,"bugs_severity":{},"status_breakdown":{},"link":null,"scope":"none"},"historical_compromise":null,"recommendation":{"action":"update_required","issues":["Low health score (35/100)","1 high severity vulnerabilities"],"use_version":"v7.0.1+incompatible","version_hint":"Update to >= 1.1.4-0.20170531185407-738c10fa1b58 to fix known vulnerabilities","summary":"github.com/apache/trafficcontrol@v7.0.1+incompatible has vulnerabilities — update to latest"},"version_scoped":null,"requested_version":null,"_cache":"hit","_response_ms":0,"_powered_by":"depscope.dev — free package intelligence for AI agents","typosquat":{"is_suspected":false},"maintainer_trust":{"available":false},"malicious":{"is_malicious":false},"scorecard":{"available":false},"quality":{"available":false}}