V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2025-31650
ANC
HighConfirmedExploit available

Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incom…

CVSS
7.5
High
EPSS
0.66
p99
Published
2025-01-01
Updated
2025-01-01
Description

Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service. This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.90 though 8.5.100. Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue.

Tags · CWE
Pre-auth
CWE-459
Affected products
Tomcat 9.0.76–9.0.104Tomcat 10.1.10–10.1.40Tomcat 11.0.1–11.0.6Tomcat
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Timeline
2025-01-01
Published
2025-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: N
None (N)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.664 · p99
Known exploited (KEV)
No
Known exploits — Сканер-ВС
52318
exploitdb · https://www.exploit-db.com/exploits/52318
Enterprise
CVE-2025-31650
github-poc · https://github.com/B1gN0Se/Tomcat-CVE-2025-31650
Enterprise
Affected products
ProductVendorStatus
Tracked
Tracked
tomcat10Tracked
tomcat10Tracked
tomcat10Tracked
tomcat10Tracked
tomcat10Tracked
tomcat11Tracked
tomcat9Tracked
tomcat9Tracked
tomcat9Tracked
tomcat9Tracked
tomcat9Tracked
tomcat9Tracked
tomcat9Tracked
tomcat*Tracked
Source databases
ANC
DEB
CVE
UBU
Related vulnerabilities