Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.apache.tomcat/tomcat-coyote
  4. ›
  5. CVE-2025-31650

CVE-2025-31650: Apache Tomcat Denial of Service via invalid HTTP priority header

April 28, 2025 (updated May 6, 2025)

Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service.

This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5.

Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue.

References

  • github.com/advisories/GHSA-3p2h-wqq4-wf4h
  • github.com/apache/tomcat
  • github.com/apache/tomcat/commit/1eef1dc459c45f1e421d8bd25ef340fc1cc34edc
  • github.com/apache/tomcat/commit/40ae788c2e64d018b4e58cd4210bb96434d0100d
  • github.com/apache/tomcat/commit/75554da2fc5574862510ae6f0d7b3d78937f1d40
  • github.com/apache/tomcat/commit/8cc3b8fb3f2d8d4d6a757e014f19d1fafa948a60
  • github.com/apache/tomcat/commit/b7674782679e1514a0d154166b1d04d38aaac4a9
  • github.com/apache/tomcat/commit/b98e74f517b36929f4208506e5adad22cb767baa
  • github.com/apache/tomcat/commit/cba1a0fe1289ee7f5dd46c61c38d1e1ac5437bff
  • github.com/apache/tomcat/commit/ded0285b96b4d3f5560dfc8856ad5ec4a9b50ba9
  • github.com/apache/tomcat/commit/f619e6a05029538886d5a9d987925d573b5bb8c2
  • lists.apache.org/thread/j6zzk0y3yym9pzfzkq5vcyxzz0yzh826
  • nvd.nist.gov/vuln/detail/CVE-2025-31650
  • tomcat.apache.org/security-10.html
  • tomcat.apache.org/security-11.html
  • tomcat.apache.org/security-9.html

Code Behaviors & Features

Detect and mitigate CVE-2025-31650 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions starting from 9.0.76 before 9.0.104, all versions starting from 10.1.10 before 10.1.40, all versions starting from 11.0.0-M2 before 11.0.6

Fixed versions

  • 9.0.104
  • 10.1.40
  • 11.0.6

Solution

Upgrade to versions 10.1.40, 11.0.6, 9.0.104 or above.

Impact 7.5 HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Learn more about CVSS

Weakness

  • CWE-459: Incomplete Cleanup
  • CWE-460: Improper Cleanup on Thrown Exception

Source file

maven/org.apache.tomcat/tomcat-coyote/CVE-2025-31650.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:06 +0000.