CVE-2025-31650

Published Apr 28, 2025

Last updated 4 months ago

Overview

Description
Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service. This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.90 though 8.5.100. Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue.
Source
security@apache.org
NVD status
Modified
Products
tomcat

Risk scores

CVSS 3.1

Type
Primary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Weaknesses

security@apache.org
CWE-459
nvd@nist.gov
CWE-459

Social media

Hype score
Not currently trending
  1. 🚨 Critical Tomcat Security Alert 🚨 Apache Tomcat has a new vulnerability (CVE-2025-31650) that could lead to memory leaks and downtime! 😱 Learn how to protect your system. 👉 Full details & fixes: https://t.co/RP4XuNEQeR #CVE202531650 #ApacheTomcat #CyberSecuri

    @tomitribe

    28 Jul 2025

    24 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-31650: Critical Apache Tomcat DoS Vulnerability - Deconstructing the "TomcatKiller" Attack 👉 https://t.co/MlHSjTi818

    @1337Sheets

    24 Jun 2025

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. A PoC exploit for Apache Tomcat's CVE-2025-31650 reveals a DoS vulnerability impacting versions 9.0.76–9.0.102, 10.1.10–10.1.39, and 11.0.0-M2–11.0.5. Improper input handling leads to memory leaks & potential OOM errors. Update to mitigate! ⚠️ #Apache #V… https://

    @TweetThreatNews

    7 Jun 2025

    93 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 Atenção, devs! Vulnerabilidade crítica no Apache Tomcat HTTP/2 (CVE-2025-31650) permite ataques DoS com headers de prioridade malformados. 💥 Atualize para as versões 9.0.104, 10.1.40 ou 11.0.6 JÁ! #Cybersecurity #ApacheTomcat #DoS https://t.co/yzVu5nmEf0

    @fernandokarl

    6 Jun 2025

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. ⚠️Múltiples vulnerabilidades en HPE Telco Service Orchestrator ❗CVE-2025-31650 ❗CVE-2025-31651 ➡️Más info: https://t.co/Z5eQBrRz1i https://t.co/7NBvluSTqO

    @CERTpy

    5 Jun 2025

    96 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 CVE-2025-31650/31651 Patched! openSUSE 15.6 Tomcat 10.1.40 update is LIVE. ▶️ zypper in -t patch openSUSE-SLE-15.6-2025-1537=1 Details: 👉 https://t.co/a96scqdMqe #LinuxSecurity https://t.co/0SoBLUqvhb

    @Cezar_H_Linux

    13 May 2025

    27 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Apache Tomcat の脆弱性 CVE-2025-31650/31651 が FIX:DoS とルール・バイパスの恐れ https://t.co/qd4baOiT2c Apache Tomcat に新たな脆弱性が発見されました。なお、同ツールでは、3月以降から別の脆弱性 CVE-2025-24813 の悪用が

    @iototsecnews

    12 May 2025

    289 Impressions

    1 Retweet

    0 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  8. 【CVE-2025-31650・CVE-2025-31651】2つの重大な脆弱性修正を含む最新安定版「Tomcat 11.0.6」へのアップデートのススメ https://t.co/z0dDhgH2sz @nikkeimatomeより

    @nikkeimatome

    9 May 2025

    10 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. [JVNVU#93256936] Apache Tomcatにおける複数の脆弱性(CVE-2025-31650、CVE-2025-31651) https://t.co/spHVEWtXLC #jvn #脆弱性 #セキュリティ

    @jpsecuritynews

    9 May 2025

    27 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. JVNVU#93256936 Apache Tomcatにおける複数の脆弱性(CVE-2025-31650、CVE-2025-31651) https://t.co/ATFp9a3QiB ご利用の方は早めの対応を。

    @Syynya

    8 May 2025

    31 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. JVNVU#93256936: Apache Tomcatにおける複数の脆弱性(CVE-2025-31650、CVE-2025-31651) https://t.co/jtIzMisJnV

    @Luke06121

    8 May 2025

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. JVN: Apache Tomcatにおける複数の脆弱性(CVE-2025-31650、CVE-2025-31651) https://t.co/ce5RtazJ4l

    @AileenWoodstock

    8 May 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 【CVE-2025-31650】Apache Tomcatに深刻なDoS脆弱性、メモリリーク問題でサービス停止の危険性 – / XEXEQ(ゼゼック) https://t.co/OQbwWkxswC

    @01ra66it

    8 May 2025

    934 Impressions

    3 Retweets

    13 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  14. [2025/05/08 10:00 公表] Apache Tomcatにおける複数の脆弱性(CVE-2025-31650、CVE-2025-31651) https://t.co/zu1zoiNG7t

    @jvnjp

    8 May 2025

    269 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    1 Quote

  15. 🚨 CVE-2025-31650: High-severity Tomcat DoS flaw lets attackers crash servers via malformed HTTP Priority headers. Affected: 9.0.76–9.0.102 10.1.10–10.1.39 11.0.0-M2–11.0.5 Fix: Upgrade to 9.0.104+/10.1.40+/11.0.6+. ⚠ Exploitable remotely! #PatchNow #CyberSecurity h

    @NullShadowX0

    2 May 2025

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  16. CVE-2025-31650 : TomcatKiller เครื่องมือที่ออกแบบมาเพื่อตรวจจับช่องโหว่ CVE-2025-31650 ใน Apache Tomcat (รุ่น 10.1.10 ถึง 10.1.39) https://t.co/mdfx2I4WMf https://t.co/Eg5UvlOUVO

    @freedomhack101

    2 May 2025

    45 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  17. CVE-2025-31650 : TomcatKiller Una herramienta diseñada para detectar la vulnerabilidad CVE-2025-31650 en Apache Tomcat (versiones 10.1.10 a 10.1.39) https://t.co/Tb9RfNX4Dk https://t.co/OibjmunHxw

    @elhackernet

    1 May 2025

    2556 Impressions

    13 Retweets

    44 Likes

    11 Bookmarks

    0 Replies

    0 Quotes

  18. GitHub - absholi7ly/TomcatKiller-CVE-2025-31650: A tool designed to detect the vulnerability **CVE-2025-31650** in Apache Tomcat (versions 10.1.10 to 10.1.39) - https://t.co/GstUbdQwe6

    @piedpiper1616

    30 Apr 2025

    2767 Impressions

    22 Retweets

    76 Likes

    39 Bookmarks

    0 Replies

    0 Quotes

  19. ⚡️The vulnerability details are now available: https://t.co/hCrWJgiraj 🚨Apache Tomcat Alert🚨 CVE-2025-31650: Attackers can bypass rules & CRASH servers with a crafty DoS attack! Malformed HTTP headers exploit a memory leak, triggering OutOfMemory chaos. 🔥PoC fr

    @zoomeye_team

    30 Apr 2025

    673 Impressions

    3 Retweets

    15 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  20. ⚡️The vulnerability details are now available: https://t.co/hCrWJgiraj 🚨Apache Tomcat Alert🚨 CVE-2025-31650: Attackers can bypass rules & CRASH servers with a crafty DoS attack! Malformed HTTP headers exploit a memory leak, triggering OutOfMemory chaos. 🔥PoC: h

    @zoomeye_team

    30 Apr 2025

    60 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  21. 🚨Poc: CVE-2025-31650 Denial of Service via Invalid HTTP Prioritization Header ( #Apache #Tomcat ) https://t.co/cpES5szeWI https://t.co/RIbSD2y838

    @absholi7ly

    30 Apr 2025

    135 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  22. ⚠️Vulnerabilidades en Apache Tomcat ❗CVE-2025-31650 ❗CVE-2025-31651 ➡️Más info: https://t.co/t8hU9AY3cz https://t.co/K85gRf1v9V

    @CERTpy

    29 Apr 2025

    125 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. 아파치 톰캣(Tomcat) 보안취약점(CVE-2025-31650, CVE-2025-31651) 패치 설치 권고 https://t.co/kdW3HaBWoS

    @virusmyths

    29 Apr 2025

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  24. Apache Tomcatにおいて重大な脆弱性(CVE-2025-31650)が発見され、攻撃者がHTTP Priorityヘッダーを悪用してDoS(サービス拒否)攻撃を実行できる危険性がある。メモリリークを引き起こしサーバをクラッシュさせる恐

    @yousukezan

    29 Apr 2025

    7731 Impressions

    45 Retweets

    117 Likes

    39 Bookmarks

    0 Replies

    1 Quote

  25. 🚨Alert🚨 CVE-2025-31650: Denial of Service via Invalid HTTP Prioritization Header & CVE-2025-31651: Rewrite Rule Bypass 📊10.6M+ Services are found on the https://t.co/ysWb28Crld yearly. 🔗Hunter Link:https://t.co/Pf8A56s3ZW 👇Query HUNTER : https://t.co/q9rtuGgxk7

    @HunterMapping

    29 Apr 2025

    2996 Impressions

    31 Retweets

    75 Likes

    25 Bookmarks

    0 Replies

    0 Quotes

  26. Apache Tomcat Security Update Fixes DoS and Rewrite Rule Bypass Flaws Apache Tomcat patches CVE-2025-31650 and CVE-2025-31651 to fix denial of service and rewrite rule bypass issues. Upgrade now to stay secure. https://t.co/WPVQNtl8bT

    @the_yellow_fall

    29 Apr 2025

    288 Impressions

    3 Retweets

    0 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  27. CVE-2025-31650 Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the faile… https://t.co/UuMd7jjgYN

    @CVEnew

    28 Apr 2025

    423 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations