CVE-2024-52317
published 2024-11-18CVE-2024-52317: Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to…
PriorityP341medium6.5CVSS 3.1
AVNACLPRNUINSUCLILAN
EPSS
2.02%
78.8th percentile
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests
could lead to request and/or response mix-up between users.
This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95.
Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.27 < 10.1.31 | 10.1.31 |
| apache | tomcat | >= 9.0.92 < 9.0.96 | 9.0.96 |
| apache_software_foundation | apache_tomcat | 10.1.27 – 10.1.30 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M23 – 11.0.0-M26 | — |
| apache_software_foundation | apache_tomcat | 9.0.92 – 9.0.95 | — |
| debian | tomcat10 | < tomcat10 10.1.31-1 (forky) | tomcat10 10.1.31-1 (forky) |
| debian | tomcat9 | < tomcat10 10.1.31-1 (forky) | tomcat10 10.1.31-1 (forky) |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
osv6.5MEDIUM
vendor_ubuntu9.8CRITICAL
vendor_debian6.5LOW
vendor_redhat6.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2025-08-20·CVSS 9.8
CVE-2024-50379 [CRITICAL] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat did not correctly handle case sensitivity.
An attacker could possibly use this issue to bypass authentication
mechanisms. (CVE-2025-46701)
Elysee Franchuk discovered that Tomcat did not correctly limit the number
of attributes for a session. An attacker could possibly use this issue to
cause a denial of service. This issue only affected Ubuntu 24.04 LTS.
(CVE-2024-54677)
It was discovered that Tomcat did not correctly sanitize certain URLs. An
attacker could possibly use this issue to bypass authentication
mechanisms. (CVE-2025-31651)
It was discovered that Tomcat did not correctly handle certain malformed
HTTP headers,
which could lead to a memory leak. An attacker could
Red Hat
tomcat: Apache Tomcat: Request/response mix-up with HTTP/2
vendor_redhat·2024-11-18·CVSS 6.5
CVE-2024-52317 [MEDIUM] CWE-326 tomcat: Apache Tomcat: Request/response mix-up with HTTP/2
tomcat: Apache Tomcat: Request/response mix-up with HTTP/2
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests
could lead to request and/or response mix-up between users.
This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95.
Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.
A flaw was found in Apache Tomcat HTTP/2 handling. This vulnerability allows a request or response mix-up between users via incorrect recycling of request and response objects.
Package: tomcat6 (Red Hat Enterprise Linux 6) - Not affected
Package: tomcat (Red Hat Enterprise Linux 7) - Not affected
Package: pki-
Debian
CVE-2024-52317: tomcat10 - Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect...
vendor_debian·2024·CVSS 6.5
CVE-2024-52317 [MEDIUM] CVE-2024-52317: tomcat10 - Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect...
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95. Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.
Scope: local
bookworm: resolved
forky: resolved (fixed in 10.1.31-1)
sid: resolved (fixed in 10.1.31-1)
trixie: resolved (fixed in 10.1.31-1)
OSV
Apache Tomcat Request and/or response mix-up
osv·2024-11-18
CVE-2024-52317 [MEDIUM] Apache Tomcat Request and/or response mix-up
Apache Tomcat Request and/or response mix-up
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users.
This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95.
Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.
OSV
CVE-2024-52317: Incorrect object re-cycling and re-use vulnerability in Apache Tomcat
osv·2024-11-18·CVSS 6.5
CVE-2024-52317 [MEDIUM] CVE-2024-52317: Incorrect object re-cycling and re-use vulnerability in Apache Tomcat
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95. Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.
GHSA
Apache Tomcat Request and/or response mix-up
ghsa·2024-11-18
CVE-2024-52317 [MEDIUM] CWE-326 Apache Tomcat Request and/or response mix-up
Apache Tomcat Request and/or response mix-up
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users.
This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95.
Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue.
No detection rules found.
No public exploits indexed.
2024-11-18
Published