PT-2025-18102 · Apache+11 · Apache Tomcat+13
Mark Thomas
·
Published
2025-04-08
·
Updated
2026-06-08
·
CVE-2025-31650
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat versions 8.5.90 through 8.5.100
Apache Tomcat versions 9.0.76 through 9.0.102
Apache Tomcat versions 10.1.10 through 10.1.39
Apache Tomcat versions 11.0.0-M2 through 11.0.5
Description
Improper input validation in Apache Tomcat occurs due to incorrect error handling of invalid HTTP priority headers. This failure leads to an incomplete clean-up of failed requests, resulting in a memory leak. A remote attacker can exploit this by sending a large volume of specially crafted HTTP requests to trigger an
OutOfMemoryException, causing a denial of service.Recommendations
Upgrade to version 9.0.104 for affected 9.0.x versions.
Upgrade to version 10.1.40 for affected 10.1.x versions.
Upgrade to version 11.0.6 for affected 11.0.x versions.
As a temporary workaround, restrict or filter invalid HTTP priority headers to minimize the risk of exploitation.
Exploit
Fix
DoS
RCE
Improper Encoding or Escaping of Output
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Almalinux
Apache Tomcat
Bamboo
Bitbucket
Centos
Confluence
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu