PT-2025-18102 · Apache+11 · Apache Tomcat+13

Mark Thomas

·

Published

2025-04-08

·

Updated

2026-06-08

·

CVE-2025-31650

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 8.5.90 through 8.5.100 Apache Tomcat versions 9.0.76 through 9.0.102 Apache Tomcat versions 10.1.10 through 10.1.39 Apache Tomcat versions 11.0.0-M2 through 11.0.5
Description Improper input validation in Apache Tomcat occurs due to incorrect error handling of invalid HTTP priority headers. This failure leads to an incomplete clean-up of failed requests, resulting in a memory leak. A remote attacker can exploit this by sending a large volume of specially crafted HTTP requests to trigger an OutOfMemoryException, causing a denial of service.
Recommendations Upgrade to version 9.0.104 for affected 9.0.x versions. Upgrade to version 10.1.40 for affected 10.1.x versions. Upgrade to version 11.0.6 for affected 11.0.x versions. As a temporary workaround, restrict or filter invalid HTTP priority headers to minimize the risk of exploitation.

Exploit

Fix

DoS

RCE

Improper Encoding or Escaping of Output

Related Identifiers

ALSA-2025:11332
ALSA-2025:11333
ALSA-2025:11335
ALSA-2025_11333
ALSA-2025_11335
ALSA-2025_16880
ALT-PU-2025-10241
ALT-PU-2025-10635
ALT-PU-2025-10912
ALT-PU-2025-13307
ALT-PU-2025-8715
BDU:2025-05707
BDU:2025-05708
BIT-TOMCAT-2025-31650
CESA-2025_11333
CLEANSTART-2026-MR27796
CVE-2025-31650
DLA-4244-1
GHSA-3P2H-WQQ4-WF4H
INFSA-2025_11333
INFSA-2025_11335
MGASA-2025-0145
OESA-2025-1484
OPENSUSE-SU-2025:15048-1
OPENSUSE-SU-2025:15049-1
OPENSUSE-SU-2025_1521-1
OPENSUSE-SU-2025_1537-1
RHSA-2025:11332
RHSA-2025:11333
RHSA-2025:11334
RHSA-2025:11335
RHSA-2025:11381
RHSA-2025:11382
RHSA-2025:3608
RHSA-2025:4521
RHSA-2025_11333
RHSA-2025_11335
SUSE-SU-2025:01521-1
SUSE-SU-2025:01537-1
SUSE-SU-2025:1521-1
SUSE-SU-2025:1537-1
SUSE-SU-2025_01521-1
SUSE-SU-2025_01537-1
SUSE-SU-2025_1521-1
SUSE-SU-2025_1537-1
USN-7705-1

Affected Products

Alt Linux
Almalinux
Apache Tomcat
Bamboo
Bitbucket
Centos
Confluence
Debian
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu