CVE-2024-24549
published 2024-03-13CVE-2024-24549: Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request…
PriorityP356high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
23.07%
97.5th percentile
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.0 < 10.1.19 | 10.1.19 |
| apache | tomcat | >= 8.5.0 < 8.5.99 | 8.5.99 |
| apache | tomcat | >= 9.0.0 < 9.0.86 | 9.0.86 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.18 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.0-M16 | — |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.98 | — |
| apache_software_foundation | apache_tomcat | 9.0.0-M1 – 9.0.85 | — |
| atlassian | bitbucket_data_center | — | — |
| debian | debian_linux | — | — |
| debian | tomcat10 | < tomcat10 10.1.6-1+deb12u2 (bookworm) | tomcat10 10.1.6-1+deb12u2 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.6-1+deb12u2 (bookworm) | tomcat10 10.1.6-1+deb12u2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Target HTTP/2 request processing in Apache Tomcat; the vulnerability is triggered when an HTTP/2 request exceeds configured limits for headers, and the stream is not reset until all headers are processed — monitor for abnormally large or excessive HTTP/2 HEADERS frames sent to Tomcat instances ↗
- →Flag Apache Tomcat versions in the affected ranges: 8.5.0–8.5.98, 9.0.0-M1–9.0.85, 10.1.0-M1–10.1.18, 11.0.0-M1–11.0.0-M16 as vulnerable targets for this DoS attack vector over HTTP/2 ↗
- ·The DoS condition is gated by configured header limits in Tomcat's HTTP/2 connector; review and tighten maxHeaderCount, maxHeaderSize, and related HTTP/2 limits to reduce the attack surface while patching is pending ↗
- ·The fix was introduced in commit 0cac540a for the 8.5.x branch; verify patch application by confirming the commit is present in deployed Tomcat builds ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_apache7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2025-06-09·CVSS 4.3
CVE-2024-34750 [MEDIUM] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in tomcat8, tomcat9, tomcat10.
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a reverse
proxy. An attacker could possibly use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-28708)
It was discovered that Tomcat incorrectly recycled
certain objects, which could lead to information leaking from one request
to the next. An attacker could potentially use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubunt
Oracle
Oracle Oracle Autonomous Health Framework Risk Matrix: Trace File Analyzer (Apache Tomcat) — CVE-2024-24549
vendor_oracle·2025-04-15·CVSS 7.5
CVE-2024-24549 [HIGH] Oracle Oracle Autonomous Health Framework Risk Matrix: Trace File Analyzer (Apache Tomcat) — CVE-2024-24549
Oracle Oracle Autonomous Health Framework Risk Matrix: Trace File Analyzer (Apache Tomcat) vulnerability
CVE: CVE-2024-24549
CVSS: 7.5
Protocol: HTTP/2
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2025 (APR 2025)
Atlassian
CVE-2024-24549: DoS (Denial of Service) org.apache.tomcat.embed:tomcat-embed-core Dependency in Bitbucket Data Center and Server
vendor_atlassian·2024-11-19·CVSS 7.5
CVE-2024-24549 [HIGH] CVE-2024-24549: DoS (Denial of Service) org.apache.tomcat.embed:tomcat-embed-core Dependency in Bitbucket Data Center and Server
CVE-2024-24549: DoS (Denial of Service) org.apache.tomcat.embed:tomcat-embed-core Dependency in Bitbucket Data Center and Server
DoS (Denial of Service) org.apache.tomcat.embed:tomcat-embed-core Dependency in Bitbucket Data Center and Server
CVE: CVE-2024-24549
Affected products: Bitbucket Data Center
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache Tomcat) — CVE-2024-24549
vendor_oracle·2024-10-15·CVSS 7.5
CVE-2024-24549 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Core (Apache Tomcat) — CVE-2024-24549
Oracle Oracle Communications Applications Risk Matrix: Core (Apache Tomcat) vulnerability
CVE: CVE-2024-24549
CVSS: 7.5
Protocol: HTTP/2
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2024 (OCT 2024)
Oracle
Oracle Oracle Commerce Risk Matrix: Workbench, Platform Services, Content Acquisition System (Apache Tomcat) — CVE-2024-24549
vendor_oracle·2024-07-15·CVSS 7.5
CVE-2024-24549 [HIGH] Oracle Oracle Commerce Risk Matrix: Workbench, Platform Services, Content Acquisition System (Apache Tomcat) — CVE-2024-24549
Oracle Oracle Commerce Risk Matrix: Workbench, Platform Services, Content Acquisition System (Apache Tomcat) vulnerability
CVE: CVE-2024-24549
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Red Hat
Tomcat: HTTP/2 header handling DoS
vendor_redhat·2024-03-13·CVSS 7.5
CVE-2024-24549 [HIGH] CWE-20 Tomcat: HTTP/2 header handling DoS
Tomcat: HTTP/2 header handling DoS
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
A vulnerability was found in the Tomcat package due to its handling of HTTP/2 requests. Specifically, when an HTTP/2 request surpasses the predetermined lim
Debian
CVE-2024-24549: tomcat10 - Denial of Service due to improper input validation vulnerability for HTTP/2 requ...
vendor_debian·2024·CVSS 7.5
CVE-2024-24549 [HIGH] CVE-2024-24549: tomcat10 - Denial of Service due to improper input validation vulnerability for HTTP/2 requ...
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
Scope: local
bookworm: resolved (fixed in 10.1.6-1+deb12u2)
forky: resolved (fixed in 10.1.20-1)
sid: resolved (fixed in 10.1.20-1)
trixie: resolved (fixed in 10.1.20-1)
Apache
Apache tomcat: CVE-2024-24549
vendor_apache·CVSS 7.5
CVE-2024-24549 [HIGH] Apache tomcat: CVE-2024-24549
Apache tomcat: CVE-2024-24549
When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed. This was fixed with commit 0cac540a . This issue was reported to the Tomcat Security Team on 24 January 2024. The issue was made public on 13 March 2024. Affects: 8.5.0 to 8.5.98 2023-11-13 Fixed in Apache Tomcat 8.5.96 Important: Request smuggling
OSV
tomcat vulnerabilities
osv·2025-06-09·CVSS 4.3
CVE-2023-28708 [MEDIUM] tomcat vulnerabilities
tomcat vulnerabilities
It was discovered that Tomcat did not include the secure attribute for
session cookies when using the RemoteIpFilter with requests from a reverse
proxy. An attacker could possibly use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-28708)
It was discovered that Tomcat incorrectly recycled
certain objects, which could lead to information leaking from one request
to the next. An attacker could potentially use this issue to leak sensitive
information. This issue was fixed for tomcat8 on Ubuntu 18.04 LTS and for
tomcat9 on Ubuntu 24.04 LTS, Ubuntu 24.10, and Ubuntu 25.04.
(CVE-2023-42795)
It was discovered that Tomcat incorrectly handled HTTP
t
GHSA
Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests
ghsa·2024-03-13
CVE-2024-24549 [MEDIUM] CWE-20 Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests
Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98.
Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
OSV
Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests
osv·2024-03-13
CVE-2024-24549 [MEDIUM] Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests
Apache Tomcat Denial of Service due to improper input validation vulnerability for HTTP/2 requests
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98.
Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
OSV
CVE-2024-24549: Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat
osv·2024-03-13·CVSS 7.5
CVE-2024-24549 [HIGH] CVE-2024-24549: Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.
No detection rules found.
No public exploits indexed.
https://lists.apache.org/thread/4c50rmomhbbsdgfjsgwlb51xdwfjdcvghttp://www.openwall.com/lists/oss-security/2024/03/13/3https://lists.apache.org/thread/4c50rmomhbbsdgfjsgwlb51xdwfjdcvghttps://lists.debian.org/debian-lts-announce/2024/04/msg00001.htmlhttps://lists.fedoraproject.org/archives/list/[email protected]/message/3UWIS5MMGYDZBLJYT674ZI5AWFHDZ46B/https://lists.fedoraproject.org/archives/list/[email protected]/message/736G4GPZWS2DSQO5WKXO3G6OMZKFEK55/https://security.netapp.com/advisory/ntap-20240402-0002/
2024-03-13
Published