#VU107996 Improper error handling in Apache Tomcat - CVE-2025-31650
Published: April 28, 2025 / Updated: July 3, 2025
Apache Tomcat
Apache Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient error handling for certain invalid HTTP priority headers. A remote attacker can send a large amount of specially crafted HTTP requests to the server and consume all available memory, resulting in a denial of service condition.