#VU29723 Infinite loop in Apache Tomcat - CVE-2020-13935
Published: July 14, 2020 / Updated: June 2, 2022
Apache Tomcat
Apache Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop when processing payload length in a WebSocket frame. A remote attacker can send a specially crafted request to the application, consume all available system resources and cause denial of service conditions.