CVE-2025-31650 Details
Description
Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service. This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.90 though 8.5.100. Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue.
A denial-of-service vulnerability has been identified in Apache Tomcat versions 9.0.76 prior to 9.0.102, 10.1.10 prior to 10.1.39, and 11.0.0-M2 prior to 11.0.5. The issue arises from improper input validation and incorrect error handling of certain invalid HTTP priority headers. This flaw causes incomplete cleanup of failed requests, leading to memory leaks. If a large number of such requests are processed, they can exhaust available memory, triggering an OutOfMemoryException and causing a denial-of-service condition.
Users are advised to upgrade to Apache Tomcat versions 9.0.104, 10.1.40, or 11.0.6, all of which include the necessary fix. Note that while this issue was addressed in Apache Tomcat 9.0.103, that version is not available due to a failed release vote, so users must upgrade to 9.0.104.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html | CVE | |
| http://www.openwall.com/lists/oss-security/2025/04/28/2 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/j6zzk0y3yym9pzfzkq5vcyxzz0yzh826 | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-459 | Incomplete Cleanup | [email protected] |
| CWE-459 | Incomplete Cleanup | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache tomcat | >= 9.0.76, < 9.0.104 >= 10.1.10, < 10.1.40 >= 11.0.1, < 11.0.6 11.0.0 milestone10 11.0.0 milestone11 11.0.0 milestone12 11.0.0 milestone13 11.0.0 milestone14 11.0.0 milestone15 11.0.0 milestone16 11.0.0 milestone17 11.0.0 milestone18 11.0.0 milestone19 11.0.0 milestone2 11.0.0 milestone20 11.0.0 milestone21 11.0.0 milestone22 11.0.0 milestone23 11.0.0 milestone24 11.0.0 milestone25 11.0.0 milestone3 11.0.0 milestone4 11.0.0 milestone5 11.0.0 milestone6 11.0.0 milestone7 11.0.0 milestone8 11.0.0 milestone9 |
CPE
Remediation
| |
Change History
10 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 3, 2025 | CVE Modified | CVE |
| Aug 8, 2025 | CVE Modified | [email protected] |
| Aug 7, 2025 | CVE Modified | [email protected] |
| May 6, 2025 | CVE Modified | CISA-ADP |
| May 6, 2025 | CVE Modified | [email protected] |
| May 5, 2025 | Initial Analysis | [email protected] |
| Apr 28, 2025 | CVE Modified | CVE |
| Apr 28, 2025 | New CVE Received | [email protected] |