GHSA-3p2h-wqq4-wf4h
Apache Tomcat Denial of Service via invalid HTTP priority header
Quick fix
GHSA-3p2h-wqq4-wf4h — org.apache.tomcat:tomcat-coyote: upgrade to the fixed version with the command below.
# pom.xml: bump <version>9.0.104</version> for org.apache.tomcat:tomcat-coyoteDetails
Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service.
This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.90 though 8.5.100.
Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
9.0.76Fixed in: 9.0.104# pom.xml: bump <version>9.0.104</version> for org.apache.tomcat:tomcat-coyote10.1.10Fixed in: 10.1.40# pom.xml: bump <version>10.1.40</version> for org.apache.tomcat:tomcat-coyote11.0.0-M2Fixed in: 11.0.6# pom.xml: bump <version>11.0.6</version> for org.apache.tomcat:tomcat-coyote9.0.76Fixed in: 9.0.104# pom.xml: bump <version>9.0.104</version> for org.apache.tomcat.embed:tomcat-embed-core10.1.10Fixed in: 10.1.40# pom.xml: bump <version>10.1.40</version> for org.apache.tomcat.embed:tomcat-embed-core11.0.0-M2Fixed in: 11.0.6# pom.xml: bump <version>11.0.6</version> for org.apache.tomcat.embed:tomcat-embed-core8.5.0No fixed version published yet for org.apache.tomcat:tomcat-coyote (maven). Pin to a known-safe version or switch to an alternative.
8.5.0No fixed version published yet for org.apache.tomcat.embed:tomcat-embed-core (maven). Pin to a known-safe version or switch to an alternative.
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-31650[ADVISORY]
- https://github.com/apache/tomcat/commit/1eef1dc459c45f1e421d8bd25ef340fc1cc34edc[WEB]
- https://github.com/apache/tomcat/commit/40ae788c2e64d018b4e58cd4210bb96434d0100d[WEB]
- https://github.com/apache/tomcat/commit/75554da2fc5574862510ae6f0d7b3d78937f1d40[WEB]
- https://github.com/apache/tomcat/commit/8cc3b8fb3f2d8d4d6a757e014f19d1fafa948a60[WEB]
- https://github.com/apache/tomcat/commit/b7674782679e1514a0d154166b1d04d38aaac4a9[WEB]
- https://github.com/apache/tomcat/commit/b98e74f517b36929f4208506e5adad22cb767baa[WEB]
- https://github.com/apache/tomcat/commit/cba1a0fe1289ee7f5dd46c61c38d1e1ac5437bff[WEB]
- https://github.com/apache/tomcat/commit/ded0285b96b4d3f5560dfc8856ad5ec4a9b50ba9[WEB]
- https://github.com/apache/tomcat/commit/f619e6a05029538886d5a9d987925d573b5bb8c2[WEB]
- https://github.com/apache/tomcat[PACKAGE]
- https://lists.apache.org/thread/j6zzk0y3yym9pzfzkq5vcyxzz0yzh826[WEB]
- https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html[WEB]
- https://tomcat.apache.org/security-10.html[WEB]
- https://tomcat.apache.org/security-11.html[WEB]
- https://tomcat.apache.org/security-9.html[WEB]
- http://www.openwall.com/lists/oss-security/2025/04/28/2[WEB]