Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service. This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5. Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue.
History

Mon, 28 Apr 2025 22:30:00 +0000

Type Values Removed Values Added
References

Mon, 28 Apr 2025 19:30:00 +0000

Type Values Removed Values Added
Description Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service. This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5. Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue.
Title Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
Weaknesses CWE-20
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2025-04-28T19:14:31.107Z

Updated: 2025-04-28T22:02:46.448Z

Reserved: 2025-03-31T12:13:57.705Z

Link: CVE-2025-31650

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-28T20:15:20.653

Modified: 2025-04-29T13:52:10.697

Link: CVE-2025-31650

cve-icon Redhat

No data.