A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
Update org.apache.tomcat.embed:tomcat-embed-core to 10.0.0-M5; org.apache.tomcat.embed:tomcat-embed-core to 9.0.35; org.apache.tomcat.embed:tomcat-embed-core to 8.5.55; org.apache.tomcat:tomcat to 10.0.0-M5; org.apache.tomcat:tomcat to 9.0.35; org.apache.tomcat:tomcat to 8.5.55 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanUncontrolled Resource Consumption in Apache Tomcat affects org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat:tomcat (maven), org.apache.tomcat:tomcat (maven), org.apache.tomcat:tomcat (maven). Severity is high. A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
Update org.apache.tomcat.embed:tomcat-embed-core to 10.0.0-M5; org.apache.tomcat.embed:tomcat-embed-core to 9.0.35; org.apache.tomcat.embed:tomcat-embed-core to 8.5.55; org.apache.tomcat:tomcat to 10.0.0-M5; org.apache.tomcat:tomcat to 9.0.35; org.apache.tomcat:tomcat to 8.5.55 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanUncontrolled Resource Consumption in Apache Tomcat affects org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat:tomcat (maven), org.apache.tomcat:tomcat (maven), org.apache.tomcat:tomcat (maven). Severity is high. A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=10.0.0-M1,<=10.0.0-M4 | 10.0.0-M5 |
|---|
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=9.0.0.M1,<9.0.35 | 9.0.35 |
|---|
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=8.5.0,<8.5.55 | 8.5.55 |
|---|
| org.apache.tomcat:tomcatmaven | >=10.0.0-M1,<=10.0.0-M4 | 10.0.0-M5 |
|---|
| org.apache.tomcat:tomcatmaven | >=9.0.0.M1,<9.0.35 | 9.0.35 |
|---|
| org.apache.tomcat:tomcatmaven | >=8.5.0,<8.5.55 | 8.5.55 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| org.apache.tomcat.embed:tomcat-embed-coremaven | >=10.0.0-M1,<=10.0.0-M4 | 10.0.0-M5 |
|---|
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=9.0.0.M1,<9.0.35 | 9.0.35 |
|---|
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=8.5.0,<8.5.55 | 8.5.55 |
|---|
| org.apache.tomcat:tomcatmaven | >=10.0.0-M1,<=10.0.0-M4 | 10.0.0-M5 |
|---|
| org.apache.tomcat:tomcatmaven | >=9.0.0.M1,<9.0.35 | 9.0.35 |
|---|
| org.apache.tomcat:tomcatmaven | >=8.5.0,<8.5.55 | 8.5.55 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard