Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3p2h-wqq4-wf4h

Опубликовано: 28 апр. 2025
Источник: github
Github: Прошло ревью
CVSS4: 6.6

Описание

Apache Tomcat Denial of Service via invalid HTTP priority header

Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service.

This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5.

Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue.

Пакеты

Наименование

org.apache.tomcat:tomcat-coyote

maven
Затронутые версииВерсия исправления

>= 9.0.76, <= 9.0.102

9.0.104

Наименование

org.apache.tomcat:tomcat-coyote

maven
Затронутые версииВерсия исправления

>= 10.1.10, < 10.1.40

10.1.40

Наименование

org.apache.tomcat:tomcat-coyote

maven
Затронутые версииВерсия исправления

>= 11.0.0-M2, < 11.0.6

11.0.6

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 9.0.76, <= 9.0.102

9.0.104

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 10.1.10, < 10.1.40

10.1.40

Наименование

org.apache.tomcat.embed:tomcat-embed-core

maven
Затронутые версииВерсия исправления

>= 11.0.0-M2, < 11.0.6

11.0.6

EPSS

Процентиль: 75%
0.00957
Низкий

6.6 Medium

CVSS4

Дефекты

CWE-459
CWE-460

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 2 месяцев назад

Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service. This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5. Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue.

CVSS3: 7.5
redhat
около 2 месяцев назад

Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service. This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5. Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue.

CVSS3: 7.5
nvd
около 2 месяцев назад

Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service. This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5. Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue.

CVSS3: 7.5
debian
около 2 месяцев назад

Improper Input Validation vulnerability in Apache Tomcat. Incorrect er ...

CVSS3: 7.5
fstec
около 2 месяцев назад

Уязвимость сервера приложений Apache Tomcat, связанная с неполной очисткой временных или вспомогательных ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 75%
0.00957
Низкий

6.6 Medium

CVSS4

Дефекты

CWE-459
CWE-460