7.5

CVE-2024-34750

Apache Tomcat: HTTP/2 excess header handling DoS

Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.0-M1 through 9.0.89.

The following versions were EOL at the time the CVE was created but are 
known to be affected: 8.5.0 though 8.5.100. Other EOL versions may also be affected.


Users are recommended to upgrade to version 11.0.0-M21, 10.1.25 or 9.0.90, which fixes the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Tomcat Version >= 9.0.0 < 9.0.90
Apache ≫ Tomcat Version >= 10.1.0 < 10.1.25
Apache ≫ Tomcat Version 11.0.0 Update milestone1
Apache ≫ Tomcat Version 11.0.0 Update milestone10
Apache ≫ Tomcat Version 11.0.0 Update milestone11
Apache ≫ Tomcat Version 11.0.0 Update milestone12
Apache ≫ Tomcat Version 11.0.0 Update milestone13
Apache ≫ Tomcat Version 11.0.0 Update milestone14
Apache ≫ Tomcat Version 11.0.0 Update milestone15
Apache ≫ Tomcat Version 11.0.0 Update milestone16
Apache ≫ Tomcat Version 11.0.0 Update milestone17
Apache ≫ Tomcat Version 11.0.0 Update milestone18
Apache ≫ Tomcat Version 11.0.0 Update milestone19
Apache ≫ Tomcat Version 11.0.0 Update milestone2
Apache ≫ Tomcat Version 11.0.0 Update milestone20
Apache ≫ Tomcat Version 11.0.0 Update milestone3
Apache ≫ Tomcat Version 11.0.0 Update milestone4
Apache ≫ Tomcat Version 11.0.0 Update milestone5
Apache ≫ Tomcat Version 11.0.0 Update milestone6
Apache ≫ Tomcat Version 11.0.0 Update milestone7
Apache ≫ Tomcat Version 11.0.0 Update milestone8
Apache ≫ Tomcat Version 11.0.0 Update milestone9
Netapp ≫ Ontap Tools Version 9 SwPlatform vmware_vsphere
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.6% 0.905
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

CWE-755 Improper Handling of Exceptional Conditions

The product does not handle or incorrectly handles an exceptional condition.

https://lists.apache.org/thread/4kqf0bc9gxymjc2x7v3p7dvplnl77y8l
Vendor Advisory
https://security.netapp.com/advisory/ntap-20240816-0004/
Third Party Advisory
https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html