When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
Update org.apache.tomcat.embed:tomcat-embed-core to 8.5.63; org.apache.tomcat.embed:tomcat-embed-core to 10.0.2; org.apache.tomcat.embed:tomcat-embed-core to 9.0.43; org.apache.tomcat:tomcat-coyote to 10.0.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanExposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat affects org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat:tomcat-coyote (maven). Severity is high. When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.tomcat.embed:tomcat-embed-core |
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
Update org.apache.tomcat.embed:tomcat-embed-core to 8.5.63; org.apache.tomcat.embed:tomcat-embed-core to 10.0.2; org.apache.tomcat.embed:tomcat-embed-core to 9.0.43; org.apache.tomcat:tomcat-coyote to 10.0.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanExposure of Sensitive Information to an Unauthorized Actor in Apache Tomcat affects org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat:tomcat-coyote (maven). Severity is high. When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.tomcat.embed:tomcat-embed-core |
| >=8.5.0,<8.5.63 |
| 8.5.63 |
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=10.0.0-M1,<10.0.2 | 10.0.2 |
|---|
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=9.0.0-M1,<9.0.43 | 9.0.43 |
|---|
| org.apache.tomcat:tomcat-coyotemaven | >=10.0.0-M1,<10.0.2 | 10.0.2 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| >=8.5.0,<8.5.63 |
| 8.5.63 |
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=10.0.0-M1,<10.0.2 | 10.0.2 |
|---|
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=9.0.0-M1,<9.0.43 | 9.0.43 |
|---|
| org.apache.tomcat:tomcat-coyotemaven | >=10.0.0-M1,<10.0.2 | 10.0.2 |
|---|
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard