CVE-2023-46589
published 2023-11-28CVE-2023-46589: Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82…
PriorityP348high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
2.65%
83.9th percentile
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single
request as multiple requests leading to the possibility of request
smuggling when behind a reverse proxy.
Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.0 < 10.1.16 | 10.1.16 |
| apache | tomcat | >= 8.5.0 < 8.5.96 | 8.5.96 |
| apache | tomcat | >= 9.0.0 < 9.0.83 | 9.0.83 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.15 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.0-M10 | — |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.95 | — |
| apache_software_foundation | apache_tomcat | 9.0.0-M1 – 9.0.82 | — |
| atlassian | jira_software | — | — |
| debian | tomcat10 | < tomcat10 10.1.6-1+deb12u2 (bookworm) | tomcat10 10.1.6-1+deb12u2 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.6-1+deb12u2 (bookworm) | tomcat10 10.1.6-1+deb12u2 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect HTTP requests with trailer headers that exceed the configured header size limit, which may indicate an attempt to exploit request smuggling via CVE-2023-46589 ↗
- →Monitor for HTTP request smuggling patterns at the reverse proxy layer when Apache Tomcat is deployed behind one — a single malformed chunked request with oversized trailer headers may appear as multiple requests ↗
- →Flag Apache Tomcat versions 8.5.0–8.5.95, 9.0.0-M1–9.0.82, 10.1.0-M1–10.1.15, and 11.0.0-M1–11.0.0-M10 as vulnerable in asset inventory; these ranges are confirmed affected ↗
- ·The vulnerability is only exploitable when Tomcat is deployed behind a reverse proxy; direct-exposure deployments have a reduced (but not zero) attack surface ↗
- ·Older, end-of-life Tomcat versions beyond the stated ranges may also be affected and will not receive patches ↗
- ·The fix was introduced in commit aa92971e for the 8.5.x branch; patch verification should confirm this commit is present ↗
- ·Red Hat pki-servlet-engine packages are not affected; fixes will be tracked via the Tomcat package instead ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Tomcat Improper Input Validation vulnerability
osv·2023-11-28
CVE-2023-46589 [HIGH] Apache Tomcat Improper Input Validation vulnerability
Apache Tomcat Improper Input Validation vulnerability
Improper Input Validation vulnerability in Apache Tomcat. Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82, and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.
OSV
CVE-2023-46589: Improper Input Validation vulnerability in Apache Tomcat
osv·2023-11-28·CVSS 7.5
CVE-2023-46589 [HIGH] CVE-2023-46589: Improper Input Validation vulnerability in Apache Tomcat
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.
GHSA
Apache Tomcat Improper Input Validation vulnerability
ghsa·2023-11-28
CVE-2023-46589 [HIGH] CWE-20 Apache Tomcat Improper Input Validation vulnerability
Apache Tomcat Improper Input Validation vulnerability
Improper Input Validation vulnerability in Apache Tomcat. Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82, and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.
Oracle
Oracle Oracle Retail Applications Risk Matrix: Xenvironment (Apache Tomcat) — CVE-2023-46589
vendor_oracle·2025-04-15·CVSS 7.5
CVE-2023-46589 [HIGH] Oracle Oracle Retail Applications Risk Matrix: Xenvironment (Apache Tomcat) — CVE-2023-46589
Oracle Oracle Retail Applications Risk Matrix: Xenvironment (Apache Tomcat) vulnerability
CVE: CVE-2023-46589
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Ubuntu
Tomcat vulnerability
vendor_ubuntu·2024-09-24
CVE-2023-46589 Tomcat vulnerability
Title: Tomcat vulnerability
Summary: Tomcat could allow unintended access to network services.
It was discovered that Tomcat incorrectly handled HTTP trailer headers. A
remote attacker could possibly use this issue to perform HTTP request
smuggling.
Instructions: In general, a standard system update will make all the necessary changes.
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-08-15·CVSS 7.0
[HIGH] Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateAugust 15, 2024
Alert CodeICSA-24-228-06
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.4
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Use After Free, Improper Input Validation, Deserialization of Untrusted Data, Improper Restriction of Operations
Oracle
Oracle Oracle Communications Risk Matrix: Alarms, KPI, and Measurements (Apache Tomcat) — CVE-2023-46589
vendor_oracle·2024-07-15·CVSS 7.5
CVE-2023-46589 [HIGH] Oracle Oracle Communications Risk Matrix: Alarms, KPI, and Measurements (Apache Tomcat) — CVE-2023-46589
Oracle Oracle Communications Risk Matrix: Alarms, KPI, and Measurements (Apache Tomcat) vulnerability
CVE: CVE-2023-46589
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Oracle
Oracle Oracle Big Data Spatial and Graph Risk Matrix: Big Data Graph (Apache Tomcat) — CVE-2023-46589
vendor_oracle·2024-04-15·CVSS 7.5
CVE-2023-46589 [HIGH] Oracle Oracle Big Data Spatial and Graph Risk Matrix: Big Data Graph (Apache Tomcat) — CVE-2023-46589
Oracle Oracle Big Data Spatial and Graph Risk Matrix: Big Data Graph (Apache Tomcat) vulnerability
CVE: CVE-2023-46589
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2024 (APR 2024)
Atlassian
CVE-2023-46589: from 9.12.0 (LTS) to 9.12.1 (LTS) from 9.11.0 to 9.11.3 from 9.10.0 to 9.10.2 from 9.9.0 to 9.9.2 from 9.8.0 to 9.8.2 fr
vendor_atlassian·2024-02-20·CVSS 9.1
CVE-2023-46589 [HIGH] CVE-2023-46589: from 9.12.0 (LTS) to 9.12.1 (LTS) from 9.11.0 to 9.11.3 from 9.10.0 to 9.10.2 from 9.9.0 to 9.9.2 from 9.8.0 to 9.8.2 fr
CVE-2023-46589: from 9.12.0 (LTS) to 9.12.1 (LTS) from 9.11.0 to 9.11.3 from 9.10.0 to 9.10.2 from 9.9.0 to 9.9.2 from 9.8.0 to 9.8.2 fr
from 9.12.0 (LTS) to 9.12.1 (LTS) from 9.11.0 to 9.11.3 from 9.10.0 to 9.10.2 from 9.9.0 to 9.9.2 from 9.8.0 to 9.8.2 from 9.7.0 to 9.7.2 9.6.0 from 9.5.0 to 9.5.1 from 9.4.0 (LTS) to 9.4.14 (LTS) from 9.3.0 to 9.3.3 from 9.2.0 to 9.2.1 from 9.1.0 to 9.1.1 9.0 from 8.22.0 to 8.22.6 Any earlier versions
CVE: CVE-2023-46589
Affected products: Jira Software
Oracle
Oracle Oracle Big Data Spatial and Graph Risk Matrix: Big Data Graph (Apache Tomcat) — CVE-2023-46589
vendor_oracle·2024-01-15·CVSS 7.5
CVE-2023-46589 [HIGH] Oracle Oracle Big Data Spatial and Graph Risk Matrix: Big Data Graph (Apache Tomcat) — CVE-2023-46589
Oracle Oracle Big Data Spatial and Graph Risk Matrix: Big Data Graph (Apache Tomcat) vulnerability
CVE: CVE-2023-46589
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2024 (JAN 2024)
Red Hat
tomcat: HTTP request smuggling via malformed trailer headers
vendor_redhat·2023-11-28·CVSS 7.5
CVE-2023-46589 [HIGH] CWE-444 tomcat: HTTP request smuggling via malformed trailer headers
tomcat: HTTP request smuggling via malformed trailer headers
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single
request as multiple requests leading to the possibility of request
smuggling when behind a reverse proxy.
Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.
An improper Input validation flaw was found in Apache Tomcat due to incorrect parsing of HTTP trailer headers. A trailer header
Debian
CVE-2023-46589: tomcat10 - Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 t...
vendor_debian·2023·CVSS 7.5
CVE-2023-46589 [HIGH] CVE-2023-46589: tomcat10 - Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 t...
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.
Scope: local
bookworm: resolved (fixed in 10.1.6-1+deb12u2)
forky: resolved (fixed in 10.1.16-1)
sid: resolved (fixed in 10.1.16-1)
trixie: resolved (fixed in 10.1.16-1)
Apache
Apache tomcat: CVE-2023-46589
vendor_apache·CVSS 7.5
CVE-2023-46589 [HIGH] Apache tomcat: CVE-2023-46589
Apache tomcat: CVE-2023-46589
Tomcat did not correctly parse HTTP trailer headers. A specially crafted trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. This was fixed with commit aa92971e . This issue was reported to the Tomcat Security Team on 20 October 2023. The issue was made public on 28 November 2023. Affects: 8.5.0 to 8.5.95 2023-10-10 Fixed in Apache Tomcat 8.5.94 Important: Request smuggling
No detection rules found.
No public exploits indexed.
HackerOne
Possibility of Request smuggling attack
hackerone·2023-12-22·CVSS 7.5
[HIGH] Possibility of Request smuggling attack
Possibility of Request smuggling attack
Request smuggling was possible by throwing an IOException with the upper size limit of the trailer header.
Confirmed with tomcat version 9.0.82.
* example
~~~~~~~~~~~~~~~~~~
POST /examples/test.jsp HTTP/1.1
Host: www.example.co.jp
Content-Type: application/x-www-form-urlencoded
Transfer-Encoding: chunked
Connection: KeepAlive
5
foo=b
2
ar
0
testtrailer: aaaaa...(large size)
a: GET /examples/?this_is_attack HTTP/1.1
Host: attack
~~~~~~~~~~~~~~~~~~
* Reproduce with the following steps:
```
$ git clone https://github.com/oss-aimoto/tomcat-trailer.git
$ cd tomcat-trailer
$ docker-compose build
$ docker-compose up -d
$ echo -n "testtrailer: " > 8190_EXCLUDE_COLON_SP_CR_LF.txt
$ for i in `seq 8179`; do echo -n "a"; done >> 8190_EXCLUDE_COLON_SP_CR_LF
Bugzilla
CVE-2023-46589 tomcat: HTTP request smuggling via malformed trailer headers
bugzilla·2023-11-29·CVSS 5.3
CVE-2023-46589 [MEDIUM] CVE-2023-46589 tomcat: HTTP request smuggling via malformed trailer headers
CVE-2023-46589 tomcat: HTTP request smuggling via malformed trailer headers
Affected versions:
- Apache Tomcat 11.0.0-M1 through 11.0.0-M10
- Apache Tomcat 10.1.0-M1 through 10.1.15
- Apache Tomcat 9.0.0-M1 through 9.0.82
- Apache Tomcat 8.5.0 through 8.5.95
Description:
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from
11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from
9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly
parse HTTP trailer headers. A trailer header that exceeded the header
size limit could cause Tomcat to treat a single
request as multiple requests leading to the possibility of request
smuggling when behind a reverse proxy.
Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16
onwards, 9.0.83 onw
https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxrhttps://www.openwall.com/lists/oss-security/2023/11/28/2https://lists.apache.org/thread/0rqq6ktozqc42ro8hhxdmmdjm1k1tpxrhttps://lists.debian.org/debian-lts-announce/2024/01/msg00001.htmlhttps://security.netapp.com/advisory/ntap-20231214-0009/https://www.openwall.com/lists/oss-security/2023/11/28/2
2023-11-28
Published