CVE-2024-24549

Aliases:GHSA-7w75-32cg-r6g2BIT-tomcat-2024-24549
Advisory lineage Upstream: 0 Downstream: 19
Modified
Published: 13 Mar 2024, 15:46
Last modified:29 Oct 2025, 11:56

Vulnerability Summary

Overall Risk (default)
medium
43/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
64.88% CRITICAL
65% probability +12.42%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

13 Mar 2024, 15:46
Published
Vulnerability first disclosed
29 Oct 2025, 11:56
Last Modified
Vulnerability information updated

Description

Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99 which fix the issue.

CVSS Metrics

  • v4.0HIGHScore: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U
  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 64.88% Percentile: 98%

Techniques & Countermeasures

  • CWE-20Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Affected Systems

  • apache software foundationapache tomcat

    ≥ 11.0.0-M1, ≤ 11.0.0-M16 | ≥ 10.1.0-M1, ≤ 10.1.18 | ≥ 9.0.0-M1, ≤ 9.0.85 | ≥ 8.5.0, ≤ 8.5.98

  • UnknownTomcat

    ≥ 8.5.0, < 8.5.99 | ≥ 9.0.0, < 9.0.86 | ≥ 10.1.0, < 10.1.19 | 11.0.0:milestone1 | 11.0.0:milestone10 | 11.0.0:milestone11 | 11.0.0:milestone12 | 11.0.0:milestone13 | 11.0.0:milestone14 | 11.0.0:milestone15 | 11.0.0:milestone16 | 11.0.0:milestone2 | 11.0.0:milestone3 | 11.0.0:milestone4 | 11.0.0:milestone5 | 11.0.0:milestone6 | 11.0.0:milestone7 | 11.0.0:milestone8 | 11.0.0:milestone9

  • debiandebian_linux

    10.0

  • fedoraprojectfedora

    39 | 40

  • org.apache.tomcattomcat-coyote

    ≥ 11.0.0-M1, < 11.0.0-M17 | ≥ 10.1.0-M1, < 10.1.19 | ≥ 9.0.0-M1, < 9.0.86 | ≥ 8.5.0, < 8.5.99

  • org.apache.tomcat.embedtomcat-embed-core

    ≥ 8.5.0, < 8.5.99 | ≥ 9.0.0-M1, < 9.0.86 | ≥ 10.1.0-M1, < 10.1.19 | ≥ 11.0.0-M1, < 11.0.0-M17

References (15)