CVE-2025-31650
Apache Tomcat: denial of service through invalid HTTP priority headers
Technology
Apache Tomcat
CVSS Score
7.5 / 10.0
Affected Versions
11.0.0-M2 to 11.0.5; 10.1.10 to 10.1.39; 9.0.76 to 9.0.102; end of life but known affected: 8.5.90 to 8.5.100
Upstream Fix
11.0.6; 10.1.40; 9.0.104
Published
April 28, 2025
OSSeva Coverage
Fixed upstream
Description
Incorrect error handling for some invalid HTTP priority headers left failed requests incompletely cleaned up, which leaked memory. A large number of such requests could trigger an OutOfMemoryError. Rated Important by the Tomcat security team. The issue was reported on the public bug tracker rather than disclosed privately. Fixed in 11.0.6, 10.1.40 and 9.0.104; the 9.0.103 release vote did not pass.
Is your Apache Tomcat deployment affected?
If you're running 11.0.0-M2 to 11.0.5; 10.1.10 to 10.1.39; 9.0.76 to 9.0.102; end of life but known affected: 8.5.90 to 8.5.100, you need this patch. Book a discovery call to get covered.