CVE-2025-31650

Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service.

This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5.

Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
apacheCNA
---
---
CVEADP
---
---
CISA-ADPADP
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 71%
VendorProductVersion
apachetomcat
9.0.76 ≤
𝑥
< 9.0.104
apachetomcat
10.1.10 ≤
𝑥
< 10.1.40
apachetomcat
11.0.1 ≤
𝑥
< 11.0.6
apachetomcat
11.0.0:milestone10
apachetomcat
11.0.0:milestone11
apachetomcat
11.0.0:milestone12
apachetomcat
11.0.0:milestone13
apachetomcat
11.0.0:milestone14
apachetomcat
11.0.0:milestone15
apachetomcat
11.0.0:milestone16
apachetomcat
11.0.0:milestone17
apachetomcat
11.0.0:milestone18
apachetomcat
11.0.0:milestone19
apachetomcat
11.0.0:milestone2
apachetomcat
11.0.0:milestone20
apachetomcat
11.0.0:milestone21
apachetomcat
11.0.0:milestone22
apachetomcat
11.0.0:milestone23
apachetomcat
11.0.0:milestone24
apachetomcat
11.0.0:milestone25
apachetomcat
11.0.0:milestone3
apachetomcat
11.0.0:milestone4
apachetomcat
11.0.0:milestone5
apachetomcat
11.0.0:milestone6
apachetomcat
11.0.0:milestone7
apachetomcat
11.0.0:milestone8
apachetomcat
11.0.0:milestone9
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
tomcat10
bookworm
vulnerable
bookworm (security)
vulnerable
bullseye
postponed
trixie
10.1.40-1
fixed
sid
10.1.40-1
fixed
tomcat11
trixie
11.0.6-1
fixed
sid
11.0.6-1
fixed
bullseye
postponed
tomcat9
bullseye
postponed
bullseye (security)
vulnerable
bookworm
9.0.70-2
fixed
trixie
9.0.95-1
fixed
sid
9.0.95-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
tomcat10
plucky
needed
oracular
ignored
noble
needed
jammy
dne
focal
dne
tomcat6
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
dne
xenial
not-affected
trusty
not-affected
tomcat7
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
dne
bionic
not-affected
xenial
not-affected
trusty
not-affected
tomcat8
plucky
dne
oracular
dne
noble
dne
jammy
dne
focal
dne
bionic
not-affected
xenial
not-affected
tomcat9
plucky
not-affected
oracular
not-affected
noble
not-affected
jammy
not-affected
focal
not-affected
bionic
not-affected