GHSA-7jqf-v358-p8g7

Suggest an improvement
Source
https://github.com/advisories/GHSA-7jqf-v358-p8g7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-7jqf-v358-p8g7/GHSA-7jqf-v358-p8g7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-7jqf-v358-p8g7
Aliases
Published
2024-11-07T09:30:42Z
Modified
2025-08-08T18:54:16.247208Z
Severity
  • 8.6 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H CVSS Calculator
  • 7.7 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:N/SC:N/SI:N/SA:H CVSS Calculator
Summary
Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
Details

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109.

Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue.

Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.

Database specific
{
    "severity": "HIGH",
    "github_reviewed_at": "2024-11-07T17:25:56Z",
    "cwe_ids": [
        "CWE-770"
    ],
    "nvd_published_at": "2024-11-07T08:15:13Z",
    "github_reviewed": true
}
References

Affected packages

Maven / org.apache.tomcat:tomcat-util

Package

Name
org.apache.tomcat:tomcat-util
View open source insights on deps.dev
Purl
pkg:maven/org.apache.tomcat/tomcat-util

Affected ranges

Type
ECOSYSTEM
Events
Introduced
11.0.0-M1
Fixed
11.0.0-M21

Affected versions

11.*

11.0.0-M1
11.0.0-M3
11.0.0-M4
11.0.0-M5
11.0.0-M6
11.0.0-M7
11.0.0-M9
11.0.0-M10
11.0.0-M11
11.0.0-M12
11.0.0-M13
11.0.0-M14
11.0.0-M15
11.0.0-M16
11.0.0-M17
11.0.0-M18
11.0.0-M19
11.0.0-M20

Maven / org.apache.tomcat:tomcat-util

Package

Name
org.apache.tomcat:tomcat-util
View open source insights on deps.dev
Purl
pkg:maven/org.apache.tomcat/tomcat-util

Affected ranges

Type
ECOSYSTEM
Events
Introduced
10.1.0-M1
Fixed
10.1.25

Affected versions

10.*

10.1.0-M1
10.1.0-M2
10.1.0-M4
10.1.0-M5
10.1.0-M6
10.1.0-M7
10.1.0-M8
10.1.0-M10
10.1.0-M11
10.1.0-M12
10.1.0-M14
10.1.0-M15
10.1.0-M16
10.1.0-M17
10.1.0
10.1.1
10.1.2
10.1.4
10.1.5
10.1.6
10.1.7
10.1.8
10.1.9
10.1.10
10.1.11
10.1.12
10.1.13
10.1.14
10.1.15
10.1.16
10.1.17
10.1.18
10.1.19
10.1.20
10.1.23
10.1.24

Maven / org.apache.tomcat:tomcat-util

Package

Name
org.apache.tomcat:tomcat-util
View open source insights on deps.dev
Purl
pkg:maven/org.apache.tomcat/tomcat-util

Affected ranges

Type
ECOSYSTEM
Events
Introduced
9.0.13
Fixed
9.0.90

Affected versions

9.*

9.0.13
9.0.14
9.0.16
9.0.17
9.0.19
9.0.20
9.0.21
9.0.22
9.0.24
9.0.26
9.0.27
9.0.29
9.0.30
9.0.31
9.0.33
9.0.34
9.0.35
9.0.36
9.0.37
9.0.38
9.0.39
9.0.40
9.0.41
9.0.43
9.0.44
9.0.45
9.0.46
9.0.48
9.0.50
9.0.52
9.0.53
9.0.54
9.0.55
9.0.56
9.0.58
9.0.59
9.0.60
9.0.62
9.0.63
9.0.64
9.0.65
9.0.67
9.0.68
9.0.69
9.0.70
9.0.71
9.0.72
9.0.73
9.0.74
9.0.75
9.0.76
9.0.78
9.0.79
9.0.80
9.0.81
9.0.82
9.0.83
9.0.84
9.0.85
9.0.86
9.0.87
9.0.88
9.0.89

Maven / org.apache.tomcat:tomcat-util

Package

Name
org.apache.tomcat:tomcat-util
View open source insights on deps.dev
Purl
pkg:maven/org.apache.tomcat/tomcat-util

Affected ranges

Type
ECOSYSTEM
Events
Introduced
8.5.35
Last affected
8.5.100

Affected versions

8.*

8.5.35
8.5.37
8.5.38
8.5.39
8.5.40
8.5.41
8.5.42
8.5.43
8.5.45
8.5.46
8.5.47
8.5.49
8.5.50
8.5.51
8.5.53
8.5.54
8.5.55
8.5.56
8.5.57
8.5.58
8.5.59
8.5.60
8.5.61
8.5.63
8.5.64
8.5.65
8.5.66
8.5.68
8.5.69
8.5.70
8.5.71
8.5.72
8.5.73
8.5.75
8.5.76
8.5.77
8.5.78
8.5.79
8.5.81
8.5.82
8.5.83
8.5.84
8.5.85
8.5.86
8.5.87
8.5.88
8.5.89
8.5.90
8.5.91
8.5.92
8.5.93
8.5.94
8.5.95
8.5.96
8.5.97
8.5.98
8.5.99
8.5.100

Maven / org.apache.tomcat:tomcat-util

Package

Name
org.apache.tomcat:tomcat-util
View open source insights on deps.dev
Purl
pkg:maven/org.apache.tomcat/tomcat-util

Affected ranges

Type
ECOSYSTEM
Events
Introduced
7.0.92
Last affected
7.0.109

Affected versions

7.*

7.0.92
7.0.93
7.0.94
7.0.96
7.0.99
7.0.100
7.0.103
7.0.104
7.0.105
7.0.106
7.0.107
7.0.108
7.0.109