[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2025-31650":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T08:55:32.481Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":19,"aliases":34,"duplicate_of":9,"upstream":37,"downstream":38,"duplicates":77,"related":78,"reserved_at":9,"published_at":92,"modified_at":93,"state":94,"summary":95,"references_raw":103,"kevs":180,"epss":181,"epss_history":184,"metrics":449,"affected":461},"CVE-2025-31650","Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service.\n\nThis issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5.\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.90 though 8.5.100.\n\n\nUsers are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":9,"capec":18},"CWE-459","Incomplete Cleanup","The product does not properly \"clean up\" and remove temporary or supporting resources after they have been used.","weakness","Draft","Base",[],[20],{"_key":21,"name":22,"source":23,"url":24,"maturity":25,"reliability_score":26,"verified":27,"type":28,"platforms":29,"requires_auth":9,"exploitdb":31,"metasploit":9},"52318","Apache Tomcat 10.1.39 - Denial of Service (DoS)","exploit-database","https://www.exploit-db.com/exploits/52318","poc",0.5,false,"remote",[30],"multiple",{"verified":27,"type":28,"platform":30,"file":32,"codes":33},"exploits/multiple/remote/52318.py",[7],[35,36],"GHSA-3p2h-wqq4-wf4h","BIT-tomcat-2025-31650",[],[39,41,43,45,47,49,51,53,55,57,59,61,63,65,67,69,71,73,75],{"_key":40},"SUSE-SU-2025:01521-1",{"_key":42},"UBUNTU-CVE-2025-31650",{"_key":44},"SUSE-SU-2025:1521-1",{"_key":46},"SUSE-SU-2025:1537-1",{"_key":48},"DLA-4244-1",{"_key":50},"SUSE-SU-2025:01537-1",{"_key":52},"OPENSUSE-SU-2025:15048-1",{"_key":54},"OPENSUSE-SU-2025:15049-1",{"_key":56},"MGASA-2025-0145",{"_key":58},"USN-7705-1",{"_key":60},"DEBIAN-CVE-2025-31650",{"_key":62},"RHSA-2025:11332",{"_key":64},"RHSA-2025:11333",{"_key":66},"RHSA-2025:11334",{"_key":68},"RHSA-2025:11335",{"_key":70},"RHSA-2025:11381",{"_key":72},"RHSA-2025:11382",{"_key":74},"RHSA-2025:4521",{"_key":76},"RHSA-2025:3608",[],[79,80,81,82,83,84,85,86,88,90],{"_key":40},{"_key":44},{"_key":46},{"_key":50},{"_key":52},{"_key":54},{"_key":56},{"_key":87},"CGA-757W-CC53-956R",{"_key":89},"CGA-RWP2-7VFM-8J2C",{"_key":91},"CGA-CJQX-3W5V-62CH","2025-04-28T19:14:31.107Z","2025-11-03T19:53:11.497Z","Modified",{"cisa_kev":27,"cisa_ransomware":27,"cisa_vendor":9,"epss_severity":96,"epss_score":97,"severity":98,"severity_score":99,"severity_version":100,"severity_source":101,"severity_vector":102,"severity_status":94},"medium",0.10908,"high",7.5,"v3.1","cve.org","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",[104,113,118,122,127,131,135,139,143,147,151,155,159,163,168,172,176],{"url":105,"sources":106,"tags":109},"https://lists.apache.org/thread/j6zzk0y3yym9pzfzkq5vcyxzz0yzh826",[101,107,108],"nvd","osv_maven",[110,111,112],"Vendor Advisory","Mailing List","WEB",{"url":114,"sources":115,"tags":116},"http://www.openwall.com/lists/oss-security/2025/04/28/2",[101,107,108],[111,117,112],"Third Party Advisory",{"url":119,"sources":120,"tags":121},"https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html",[101,107,108],[112],{"url":123,"sources":124,"tags":125},"https://nvd.nist.gov/vuln/detail/CVE-2025-31650",[108],[126],"Advisory",{"url":128,"sources":129,"tags":130},"https://github.com/apache/tomcat/commit/1eef1dc459c45f1e421d8bd25ef340fc1cc34edc",[108],[112],{"url":132,"sources":133,"tags":134},"https://github.com/apache/tomcat/commit/40ae788c2e64d018b4e58cd4210bb96434d0100d",[108],[112],{"url":136,"sources":137,"tags":138},"https://github.com/apache/tomcat/commit/75554da2fc5574862510ae6f0d7b3d78937f1d40",[108],[112],{"url":140,"sources":141,"tags":142},"https://github.com/apache/tomcat/commit/8cc3b8fb3f2d8d4d6a757e014f19d1fafa948a60",[108],[112],{"url":144,"sources":145,"tags":146},"https://github.com/apache/tomcat/commit/b7674782679e1514a0d154166b1d04d38aaac4a9",[108],[112],{"url":148,"sources":149,"tags":150},"https://github.com/apache/tomcat/commit/b98e74f517b36929f4208506e5adad22cb767baa",[108],[112],{"url":152,"sources":153,"tags":154},"https://github.com/apache/tomcat/commit/cba1a0fe1289ee7f5dd46c61c38d1e1ac5437bff",[108],[112],{"url":156,"sources":157,"tags":158},"https://github.com/apache/tomcat/commit/ded0285b96b4d3f5560dfc8856ad5ec4a9b50ba9",[108],[112],{"url":160,"sources":161,"tags":162},"https://github.com/apache/tomcat/commit/f619e6a05029538886d5a9d987925d573b5bb8c2",[108],[112],{"url":164,"sources":165,"tags":166},"https://github.com/apache/tomcat",[108],[167],"PACKAGE",{"url":169,"sources":170,"tags":171},"https://tomcat.apache.org/security-10.html",[108],[112],{"url":173,"sources":174,"tags":175},"https://tomcat.apache.org/security-11.html",[108],[112],{"url":177,"sources":178,"tags":179},"https://tomcat.apache.org/security-9.html",[108],[112],[],{"date":182,"score":97,"percentile":183},"2026-06-04",0.93529,[185,189,192,195,198,201,204,207,209,212,215,218,221,224,226,230,233,236,240,244,247,251,254,256,258,261,264,267,271,274,276,279,282,284,286,289,292,295,298,301,303,305,308,311,314,317,320,323,326,329,332,335,338,340,343,346,349,351,354,358,361,363,367,370,373,375,378,381,384,387,389,391,394,397,400,403,407,410,413,416,419,422,425,427,430,434,437,440,443,445],{"date":186,"score":187,"percentile":188},"2025-11-04",0.05287,0.89543,{"date":190,"score":187,"percentile":191},"2025-11-05",0.89542,{"date":193,"score":187,"percentile":194},"2025-11-06",0.8954,{"date":196,"score":187,"percentile":197},"2025-11-07",0.89546,{"date":199,"score":187,"percentile":200},"2025-11-08",0.89549,{"date":202,"score":187,"percentile":203},"2025-11-09",0.89547,{"date":205,"score":187,"percentile":206},"2025-11-10",0.89545,{"date":208,"score":187,"percentile":206},"2025-11-11",{"date":210,"score":187,"percentile":211},"2025-11-12",0.89552,{"date":213,"score":187,"percentile":214},"2025-11-13",0.89556,{"date":216,"score":187,"percentile":217},"2025-11-14",0.89559,{"date":219,"score":187,"percentile":220},"2025-11-15",0.89557,{"date":222,"score":187,"percentile":223},"2025-11-16",0.89558,{"date":225,"score":187,"percentile":214},"2025-11-17",{"date":227,"score":228,"percentile":229},"2025-11-18",0.06959,0.90533,{"date":231,"score":228,"percentile":232},"2025-11-19",0.90537,{"date":234,"score":228,"percentile":235},"2025-11-20",0.90542,{"date":237,"score":238,"percentile":239},"2025-11-21",0.09474,0.92495,{"date":241,"score":242,"percentile":243},"2025-11-22",0.10081,0.92786,{"date":245,"score":242,"percentile":246},"2025-11-23",0.9279,{"date":248,"score":249,"percentile":250},"2025-11-24",0.07476,0.91392,{"date":252,"score":249,"percentile":253},"2025-11-25",0.91395,{"date":255,"score":249,"percentile":253},"2025-11-26",{"date":257,"score":249,"percentile":253},"2025-11-27",{"date":259,"score":249,"percentile":260},"2025-11-28",0.91387,{"date":262,"score":249,"percentile":263},"2025-11-29",0.91416,{"date":265,"score":249,"percentile":266},"2025-11-30",0.91414,{"date":268,"score":269,"percentile":270},"2025-12-01",0.07119,0.91239,{"date":272,"score":269,"percentile":273},"2025-12-02",0.91237,{"date":275,"score":269,"percentile":273},"2025-12-03",{"date":277,"score":249,"percentile":278},"2025-12-04",0.91409,{"date":280,"score":249,"percentile":281},"2025-12-05",0.91411,{"date":283,"score":249,"percentile":266},"2025-12-06",{"date":285,"score":249,"percentile":281},"2025-12-07",{"date":287,"score":249,"percentile":288},"2025-12-08",0.9141,{"date":290,"score":249,"percentile":291},"2025-12-09",0.91413,{"date":293,"score":249,"percentile":294},"2025-12-10",0.9142,{"date":296,"score":249,"percentile":297},"2025-12-11",0.91424,{"date":299,"score":249,"percentile":300},"2025-12-12",0.91425,{"date":302,"score":249,"percentile":291},"2025-12-13",{"date":304,"score":249,"percentile":281},"2025-12-14",{"date":306,"score":249,"percentile":307},"2025-12-15",0.91415,{"date":309,"score":249,"percentile":310},"2025-12-16",0.91441,{"date":312,"score":249,"percentile":313},"2025-12-17",0.91449,{"date":315,"score":249,"percentile":316},"2025-12-18",0.91453,{"date":318,"score":249,"percentile":319},"2025-12-19",0.91455,{"date":321,"score":249,"percentile":322},"2025-12-20",0.91456,{"date":324,"score":249,"percentile":325},"2025-12-21",0.91457,{"date":327,"score":249,"percentile":328},"2025-12-22",0.91451,{"date":330,"score":249,"percentile":331},"2025-12-23",0.91458,{"date":333,"score":249,"percentile":334},"2025-12-24",0.91465,{"date":336,"score":249,"percentile":337},"2025-12-25",0.91466,{"date":339,"score":249,"percentile":337},"2025-12-26",{"date":341,"score":249,"percentile":342},"2025-12-27",0.915,{"date":344,"score":249,"percentile":345},"2025-12-28",0.91463,{"date":347,"score":249,"percentile":348},"2025-12-29",0.9146,{"date":350,"score":249,"percentile":337},"2025-12-30",{"date":352,"score":249,"percentile":353},"2025-12-31",0.91474,{"date":355,"score":356,"percentile":357},"2026-01-01",0.07738,0.91701,{"date":359,"score":356,"percentile":360},"2026-01-02",0.91696,{"date":362,"score":356,"percentile":360},"2026-01-03",{"date":364,"score":365,"percentile":366},"2026-01-04",0.08122,0.91888,{"date":368,"score":365,"percentile":369},"2026-01-05",0.91885,{"date":371,"score":365,"percentile":372},"2026-01-06",0.91887,{"date":374,"score":365,"percentile":372},"2026-01-07",{"date":376,"score":365,"percentile":377},"2026-01-08",0.9189,{"date":379,"score":365,"percentile":380},"2026-01-09",0.91893,{"date":382,"score":365,"percentile":383},"2026-01-10",0.91894,{"date":385,"score":365,"percentile":386},"2026-01-11",0.91886,{"date":388,"score":365,"percentile":386},"2026-01-12",{"date":390,"score":365,"percentile":386},"2026-01-13",{"date":392,"score":365,"percentile":393},"2026-01-14",0.919,{"date":395,"score":365,"percentile":396},"2026-01-15",0.91903,{"date":398,"score":365,"percentile":399},"2026-01-16",0.91905,{"date":401,"score":365,"percentile":402},"2026-01-17",0.91908,{"date":404,"score":405,"percentile":406},"2026-01-18",0.10919,0.93173,{"date":408,"score":405,"percentile":409},"2026-01-19",0.93174,{"date":411,"score":405,"percentile":412},"2026-01-20",0.93175,{"date":414,"score":365,"percentile":415},"2026-01-21",0.91914,{"date":417,"score":365,"percentile":418},"2026-01-22",0.91917,{"date":420,"score":365,"percentile":421},"2026-01-23",0.91926,{"date":423,"score":365,"percentile":424},"2026-01-24",0.91933,{"date":426,"score":365,"percentile":424},"2026-01-25",{"date":428,"score":365,"percentile":429},"2026-01-26",0.91935,{"date":431,"score":432,"percentile":433},"2026-01-27",0.03459,0.87196,{"date":435,"score":432,"percentile":436},"2026-01-28",0.87199,{"date":438,"score":432,"percentile":439},"2026-01-29",0.87201,{"date":441,"score":432,"percentile":442},"2026-01-30",0.87203,{"date":444,"score":432,"percentile":442},"2026-01-31",{"date":446,"score":447,"percentile":448},"2026-02-01",0.03285,0.86921,[450,455,457],{"source":101,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":451,"cvss_v4_0":9},{"baseScore":99,"baseSeverity":452,"vectorString":102,"impactScore":453,"exploitabilityScore":454},"HIGH",6,10,{"source":107,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":456,"cvss_v4_0":9},{"baseScore":99,"baseSeverity":452,"vectorString":102,"impactScore":453,"exploitabilityScore":454},{"source":108,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":9,"cvss_v4_0":458},{"baseScore":459,"baseSeverity":9,"vectorString":460,"impactScore":9,"exploitabilityScore":9},8.7,"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U",[462,486,549,566],{"ecosystem":9,"name":463,"vendor":464,"product":465,"cpe_part":466,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":467},"Apache Tomcat","apache software foundation","apache tomcat","a",[468,474,478,482],{"version":469,"is_range":470,"range_type":101,"version_start":471,"version_start_type":472,"version_end":473,"version_end_type":472,"fixed_in":9},">= 9.0.76, \u003C= 9.0.102",true,"9.0.76","including","9.0.102",{"version":475,"is_range":470,"range_type":101,"version_start":476,"version_start_type":472,"version_end":477,"version_end_type":472,"fixed_in":9},">= 10.1.10, \u003C= 10.1.39","10.1.10","10.1.39",{"version":479,"is_range":470,"range_type":101,"version_start":480,"version_start_type":472,"version_end":481,"version_end_type":472,"fixed_in":9},">= 11.0.0-M2, \u003C= 11.0.5","11.0.0-M2","11.0.5",{"version":483,"is_range":470,"range_type":101,"version_start":484,"version_start_type":472,"version_end":485,"version_end_type":472,"fixed_in":9},">= 8.5.90, \u003C= 8.5.100","8.5.90","8.5.100",{"ecosystem":9,"name":487,"vendor":9,"product":487,"cpe_part":9,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":488},"Tomcat",[489,494,497,501,503,505,507,509,511,513,515,517,519,521,523,525,527,529,531,533,535,537,539,541,543,545,547],{"version":490,"is_range":470,"range_type":491,"version_start":471,"version_start_type":472,"version_end":492,"version_end_type":493,"fixed_in":9},"gte9.0.76_lt9.0.104","cpe","9.0.104","excluding",{"version":495,"is_range":470,"range_type":491,"version_start":476,"version_start_type":472,"version_end":496,"version_end_type":493,"fixed_in":9},"gte10.1.10_lt10.1.40","10.1.40",{"version":498,"is_range":470,"range_type":491,"version_start":499,"version_start_type":472,"version_end":500,"version_end_type":493,"fixed_in":9},"gte11.0.1_lt11.0.6","11.0.1","11.0.6",{"version":502,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone10",{"version":504,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone11",{"version":506,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone12",{"version":508,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone13",{"version":510,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone14",{"version":512,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone15",{"version":514,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone16",{"version":516,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone17",{"version":518,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone18",{"version":520,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone19",{"version":522,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone2",{"version":524,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone20",{"version":526,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone21",{"version":528,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone22",{"version":530,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone23",{"version":532,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone24",{"version":534,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone25",{"version":536,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone3",{"version":538,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone4",{"version":540,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone5",{"version":542,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone6",{"version":544,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone7",{"version":546,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone8",{"version":548,"is_range":27,"range_type":491,"version_start":9,"version_start_type":9,"version_end":9,"version_end_type":9,"fixed_in":9},"11.0.0:milestone9",{"ecosystem":550,"name":551,"vendor":552,"product":553,"cpe_part":9,"purl_type":554,"purl_namespace":552,"purl_name":553,"source":9,"versions":555},"Maven","org.apache.tomcat:tomcat-coyote","org.apache.tomcat","tomcat-coyote","maven",[556,559,561,563],{"version":557,"is_range":470,"range_type":558,"version_start":471,"version_start_type":472,"version_end":492,"version_end_type":493,"fixed_in":9},"gte9_0_76_lt9_0_104","ecosystem",{"version":560,"is_range":470,"range_type":558,"version_start":476,"version_start_type":472,"version_end":496,"version_end_type":493,"fixed_in":9},"gte10_1_10_lt10_1_40",{"version":562,"is_range":470,"range_type":558,"version_start":480,"version_start_type":472,"version_end":500,"version_end_type":493,"fixed_in":9},"gte11_0_0_M2_lt11_0_6",{"version":564,"is_range":470,"range_type":558,"version_start":565,"version_start_type":472,"version_end":485,"version_end_type":472,"fixed_in":9},"gte8_5_0_lte8_5_100","8.5.0",{"ecosystem":550,"name":567,"vendor":568,"product":569,"cpe_part":9,"purl_type":554,"purl_namespace":568,"purl_name":569,"source":9,"versions":570},"org.apache.tomcat.embed:tomcat-embed-core","org.apache.tomcat.embed","tomcat-embed-core",[571,572,573,574],{"version":557,"is_range":470,"range_type":558,"version_start":471,"version_start_type":472,"version_end":492,"version_end_type":493,"fixed_in":9},{"version":560,"is_range":470,"range_type":558,"version_start":476,"version_start_type":472,"version_end":496,"version_end_type":493,"fixed_in":9},{"version":562,"is_range":470,"range_type":558,"version_start":480,"version_start_type":472,"version_end":500,"version_end_type":493,"fixed_in":9},{"version":564,"is_range":470,"range_type":558,"version_start":565,"version_start_type":472,"version_end":485,"version_end_type":472,"fixed_in":9}]