An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS01Y3c0LWdneDktMzZ2Z82_fQ

Moderate EPSS: 0.32437% (0.965 Percentile) EPSS:

Apache Tomcat Denial of Service via Malformed Request Headers

Affected Packages Affected Versions Fixed Versions
maven:org.apache.tomcat:tomcat >= 6.0.0, <= 6.0.18, >= 5.5.0, <= 5.5.27, >= 4.1.0, <= 4.1.39 No known fixed version
30 Dependent packages
438 Dependent repositories

Affected Version Ranges

All affected versions

Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when the Java AJP connector and mod_jk load balancing are used, allows remote attackers to cause a denial of service (application outage) via a crafted request with invalid headers, related to temporary blocking of connectors that have encountered errors, as demonstrated by an error involving a malformed HTTP Host header.

References: