Improper Input Validation vulnerability in Apache Tomcat. Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.
Update org.apache.tomcat.embed:tomcat-embed-core to 11.0.0-M12; org.apache.tomcat.embed:tomcat-embed-core to 10.1.14; org.apache.tomcat.embed:tomcat-embed-core to 9.0.81; org.apache.tomcat.embed:tomcat-embed-core to 8.5.94; org.apache.tomcat:tomcat to 11.0.0-M12; org.apache.tomcat:tomcat to 10.1.14; org.apache.tomcat:tomcat to 9.0.81; org.apache.tomcat:tomcat to 8.5.94; org.apache.tomcat:tomcat-coyote to 11.0.0-M12; org.apache.tomcat:tomcat-coyote to 10.1.14; org.apache.tomcat:tomcat-coyote to 9.0.81; org.apache.tomcat:tomcat-coyote to 8.5.94 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Tomcat Improper Input Validation vulnerability affects org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat:tomcat (maven), org.apache.tomcat:tomcat (maven), org.apache.tomcat:tomcat (maven), org.apache.tomcat:tomcat (maven), org.apache.tomcat:tomcat-coyote (maven), org.apache.tomcat:tomcat-coyote (maven), org.apache.tomcat:tomcat-coyote (maven), org.apache.tomcat:tomcat-coyote (maven). Severity is medium. Improper Input Validation vulnerability in Apache Tomcat. Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.
AI coding agents often install or upgrade packages automatically in maven. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
Improper Input Validation vulnerability in Apache Tomcat. Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.
Update org.apache.tomcat.embed:tomcat-embed-core to 11.0.0-M12; org.apache.tomcat.embed:tomcat-embed-core to 10.1.14; org.apache.tomcat.embed:tomcat-embed-core to 9.0.81; org.apache.tomcat.embed:tomcat-embed-core to 8.5.94; org.apache.tomcat:tomcat to 11.0.0-M12; org.apache.tomcat:tomcat to 10.1.14; org.apache.tomcat:tomcat to 9.0.81; org.apache.tomcat:tomcat to 8.5.94; org.apache.tomcat:tomcat-coyote to 11.0.0-M12; org.apache.tomcat:tomcat-coyote to 10.1.14; org.apache.tomcat:tomcat-coyote to 9.0.81; org.apache.tomcat:tomcat-coyote to 8.5.94 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Tomcat Improper Input Validation vulnerability affects org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat:tomcat (maven), org.apache.tomcat:tomcat (maven), org.apache.tomcat:tomcat (maven), org.apache.tomcat:tomcat (maven), org.apache.tomcat:tomcat-coyote (maven), org.apache.tomcat:tomcat-coyote (maven), org.apache.tomcat:tomcat-coyote (maven), org.apache.tomcat:tomcat-coyote (maven). Severity is medium. Improper Input Validation vulnerability in Apache Tomcat. Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.
AI coding agents often install or upgrade packages automatically in maven. A medium vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=11.0.0-M1,<11.0.0-M12 | 11.0.0-M12 |
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=10.1.0-M1,<10.1.14 | 10.1.14 |
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=9.0.0-M1,<9.0.81 | 9.0.81 |
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=8.5.0,<8.5.94 | 8.5.94 |
| org.apache.tomcat:tomcatmaven | >=11.0.0-M1,<11.0.0-M12 | 11.0.0-M12 |
| org.apache.tomcat:tomcatmaven | >=10.1.0-M1,<10.1.14 | 10.1.14 |
| org.apache.tomcat:tomcatmaven | >=9.0.0-M1,<9.0.81 | 9.0.81 |
| org.apache.tomcat:tomcatmaven | >=8.5.0,<8.5.94 | 8.5.94 |
| org.apache.tomcat:tomcat-coyotemaven | >=11.0.0-M1,<11.0.0-M12 | 11.0.0-M12 |
| org.apache.tomcat:tomcat-coyotemaven | >=10.1.0-M1,<10.1.14 | 10.1.14 |
| org.apache.tomcat:tomcat-coyotemaven | >=9.0.0-M1,<9.0.81 | 9.0.81 |
| org.apache.tomcat:tomcat-coyotemaven | >=8.5.0,<8.5.94 | 8.5.94 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=11.0.0-M1,<11.0.0-M12 | 11.0.0-M12 |
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=10.1.0-M1,<10.1.14 | 10.1.14 |
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=9.0.0-M1,<9.0.81 | 9.0.81 |
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=8.5.0,<8.5.94 | 8.5.94 |
| org.apache.tomcat:tomcatmaven | >=11.0.0-M1,<11.0.0-M12 | 11.0.0-M12 |
| org.apache.tomcat:tomcatmaven | >=10.1.0-M1,<10.1.14 | 10.1.14 |
| org.apache.tomcat:tomcatmaven | >=9.0.0-M1,<9.0.81 | 9.0.81 |
| org.apache.tomcat:tomcatmaven | >=8.5.0,<8.5.94 | 8.5.94 |
| org.apache.tomcat:tomcat-coyotemaven | >=11.0.0-M1,<11.0.0-M12 | 11.0.0-M12 |
| org.apache.tomcat:tomcat-coyotemaven | >=10.1.0-M1,<10.1.14 | 10.1.14 |
| org.apache.tomcat:tomcat-coyotemaven | >=9.0.0-M1,<9.0.81 | 9.0.81 |
| org.apache.tomcat:tomcat-coyotemaven | >=8.5.0,<8.5.94 | 8.5.94 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard