Uncontrolled Resource Consumption in Apache Tomcat
High severity
GitHub Reviewed
Published
Feb 9, 2022
to the GitHub Advisory Database
•
Updated Mar 11, 2024
Package
Affected versions
>= 10.0.0-M1, <= 10.0.0-M4
>= 9.0.0.M1, < 9.0.35
>= 8.5.0, < 8.5.55
Patched versions
10.0.0-M5
9.0.35
8.5.55
Description
Published by the National Vulnerability Database
Jun 26, 2020
Reviewed
Apr 12, 2021
Published to the GitHub Advisory Database
Feb 9, 2022
Last updated
Mar 11, 2024
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
References