Back to Vulnerability Directory
HIGHFixed upstream

CVE-2025-31650

Apache Tomcat: denial of service through invalid HTTP priority headers

Technology

Apache Tomcat

CVSS Score

7.5 / 10.0

Affected Versions

11.0.0-M2 to 11.0.5; 10.1.10 to 10.1.39; 9.0.76 to 9.0.102; end of life but known affected: 8.5.90 to 8.5.100

Upstream Fix

11.0.6; 10.1.40; 9.0.104

Published

April 28, 2025

OSSeva Coverage

Fixed upstream

Description

Incorrect error handling for some invalid HTTP priority headers left failed requests incompletely cleaned up, which leaked memory. A large number of such requests could trigger an OutOfMemoryError. Rated Important by the Tomcat security team. The issue was reported on the public bug tracker rather than disclosed privately. Fixed in 11.0.6, 10.1.40 and 9.0.104; the 9.0.103 release vote did not pass.

Upstream record: NVD · CVE.org

Is your Apache Tomcat deployment affected?

If you're running 11.0.0-M2 to 11.0.5; 10.1.10 to 10.1.39; 9.0.76 to 9.0.102; end of life but known affected: 8.5.90 to 8.5.100, you need this patch. Book a discovery call to get covered.