The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcatUpgrade tomcat-webappsUpgrade tomcat-el-3.0-apiUpgrade tomcat-docs-webappUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-jsvcUpgrade tomcat-javadocUpgrade tomcat-admin-webappsUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-libUpgrade tomcat-servlet-3.1-api | Sep 28, 2023 | Oct 14, 2021 |
| Amazon_linux | — | Upgrade tomcat8 | Nov 5, 2021 | Oct 14, 2021 |
| Apache Tomcat | — | Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 8.5.72Upgrade Apache Tomcat to 9.0.54Upgrade Apache Tomcat to 10.0.11 | Oct 15, 2021 | Oct 14, 2021 |
| Debian | — | Upgrade tomcat9 | Nov 4, 2022 | Oct 14, 2021 |
| Gentoo Linux | — | Upgrade www-servers/tomcat. | Aug 22, 2022 | Oct 14, 2021 |
| Oracle Solaris | — | Upgrade web/java-servlet/tomcat-8/tomcat-examples to version 8.5.72-11.4.40.0.1.107.1 on Solaris 11.4Upgrade web/java-servlet/tomcat-8/tomcat-admin to version 8.5.72-11.4.40.0.1.107.1 on Solaris 11.4Upgrade web/java-servlet/tomcat-8 to version 8.5.72-11.4.40.0.1.107.1 on Solaris 11.4 | Dec 13, 2021 | Oct 14, 2021 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Oct 14, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Oct 14, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub