Apache Tomcat
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*, +1 more
- >= 11.0.0-M1, <= 11.0.21
- >= 10.1.0-M1, <= 10.1.54
- >= 9.0.0.M1, <= 9.0.117
- < 9.0.0.M1
A vulnerability exists in Apache Tomcat in versions 11.0.0-M1 prior to 11.0.21, 10.1.0-M1 prior to 10.1.54, 9.0.0-M1 prior to 9.0.117, and 10.0.0-M1 prior to 10.0.27. Older, unsupported versions may also be affected. The issue arises from improper validation of HTTP/2 request headers, which could lead to unexpected application behavior if the application assumed that header values exposed through the Servlet API were compliant with the specification.
Exploitation of this vulnerability could cause applications to behave unexpectedly, particularly if they rely on the assumption that HTTP/2 headers are validated and compliant with the specification.
Users should upgrade to Apache Tomcat 11.0.22 or later, 10.1.55 or later, or 9.0.118 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.