Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89.
The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Other EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue.
Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
CVSS Details
- CVSS 3.1 Base Score: 8.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to 11.0.0Upgrade Apache Tomcat to 9.0.90Upgrade Apache Tomcat to 10.1.25Upgrade Apache Tomcat to the latest available version | Nov 7, 2024 | Nov 7, 2024 |
| Atlassian Bitbucket | — | Upgrade Atlassian Bitbucket to the latest version | Jan 21, 2026 | Jan 20, 2026 |
| Debian | — | Upgrade tomcat9Upgrade tomcat10 | Sep 25, 2024 | Sep 25, 2024 |
| Redhat_linux | — | Upgrade idm-pki-symkey-debuginfoUpgrade jssUpgrade jackson-coreUpgrade resteasyUpgrade python3-idm-pkiUpgrade bea-stax-apiUpgrade idm-pki-kraUpgrade pki-servlet-engineUpgrade jackson-annotationsUpgrade jackson-jaxrs-providersUpgrade velocityUpgrade relaxngDatatypeUpgrade xml-commons-apisUpgrade idm-pki-acmeUpgrade jackson-databindUpgrade slf4jUpgrade jackson-module-jaxb-annotationsUpgrade slf4j-jdk14Upgrade glassfish-jaxb-apiUpgrade tomcatjssUpgrade tomcat-libUpgrade idm-pki-tools-debuginfoUpgrade python-nss-debugsourceUpgrade python-nss-docUpgrade tomcat-admin-webappsUpgrade idm-pki-base-javaUpgrade tomcat-jsp-2.3-apiUpgrade apache-commons-langUpgrade jackson-jaxrs-json-providerUpgrade stax-exUpgrade glassfish-jaxb-runtimeUpgrade idm-pki-symkeyUpgrade jss-debugsourceUpgrade jss-javadocUpgrade tomcatNo solution existsUpgrade tomcat-webappsUpgrade pki-servlet-4.0-apiUpgrade pki-core-debuginfoUpgrade apache-commons-collectionsUpgrade xalan-j2Upgrade tomcat-el-3.0-apiUpgrade glassfish-jaxb-coreUpgrade jss-debuginfoUpgrade python3-nssUpgrade apache-commons-netUpgrade xmlstreambufferUpgrade xerces-j2Upgrade idm-pki-toolsUpgrade javassist-javadocUpgrade ldapjdk-javadocUpgrade jakarta-commons-httpclientUpgrade idm-pki-baseUpgrade idm-pki-caUpgrade javassistUpgrade idm-pki-serverUpgrade pki-core-debugsourceUpgrade python3-nss-debuginfoUpgrade glassfish-jaxb-txw2Upgrade xml-commons-resolverUpgrade ldapjdkUpgrade tomcat-docs-webappUpgrade tomcat-servlet-4.0-apiUpgrade xsomUpgrade glassfish-fastinfoset | Oct 31, 2024 | Sep 23, 2024 |
| Suse | — | Upgrade tomcat-libUpgrade tomcat-admin-webappsUpgrade tomcat-javadocUpgrade tomcatUpgrade tomcat-webappsUpgrade tomcat-servlet-4_0-apiUpgrade tomcat-jsp-2_3-apiUpgrade tomcat-docs-webappUpgrade tomcat-el-3_0-api | Dec 5, 2025 | Oct 2, 2024 |
| Ubuntu | — | Upgrade libtomcat9-javaUpgrade libtomcat8-java (Ubuntu Pro)Upgrade tomcat8 (Ubuntu Pro)Upgrade libtomcat10-java (Ubuntu Pro)Upgrade tomcat10 (Ubuntu Pro)Upgrade tomcat9 (Ubuntu Pro)Upgrade libtomcat9-java (Ubuntu Pro) | Jun 11, 2025 | Nov 7, 2024 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub