Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue. Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
Update org.apache.tomcat.embed:tomcat-embed-core to 11.0.0-M21; org.apache.tomcat.embed:tomcat-embed-core to 10.1.25; org.apache.tomcat.embed:tomcat-embed-core to 9.0.90; org.apache.tomcat:tomcat-coyote to 11.0.0-M21; org.apache.tomcat:tomcat-coyote to 10.1.25; org.apache.tomcat:tomcat-coyote to 9.0.90 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Tomcat Allocation of Resources Without Limits or Throttling vulnerability affects org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat:tomcat-coyote (maven), org.apache.tomcat:tomcat-coyote (maven), org.apache.tomcat:tomcat-coyote (maven), org.apache.tomcat:tomcat-coyote (maven), org.apache.tomcat:tomcat-coyote (maven). Severity is high. Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue. Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue. Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
Update org.apache.tomcat.embed:tomcat-embed-core to 11.0.0-M21; org.apache.tomcat.embed:tomcat-embed-core to 10.1.25; org.apache.tomcat.embed:tomcat-embed-core to 9.0.90; org.apache.tomcat:tomcat-coyote to 11.0.0-M21; org.apache.tomcat:tomcat-coyote to 10.1.25; org.apache.tomcat:tomcat-coyote to 9.0.90 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanApache Tomcat Allocation of Resources Without Limits or Throttling vulnerability affects org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat.embed:tomcat-embed-core (maven), org.apache.tomcat:tomcat-coyote (maven), org.apache.tomcat:tomcat-coyote (maven), org.apache.tomcat:tomcat-coyote (maven), org.apache.tomcat:tomcat-coyote (maven), org.apache.tomcat:tomcat-coyote (maven). Severity is high. Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the issue. Apache Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
AI coding agents often install or upgrade packages automatically in maven. A high vulnerability in a dependency can be pulled into a project through a normal install or update without a human reviewing the change, expanding the blast radius from a single package to every agent workspace that depends on it.
| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=11.0.0-M1,<11.0.0-M21 | 11.0.0-M21 |
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=10.1.0-M1,<10.1.25 | 10.1.25 |
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=9.0.13,<9.0.90 | 9.0.90 |
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=8.5.35,<=8.5.100 | Not reported |
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=7.0.92,<=7.0.109 | Not reported |
| org.apache.tomcat:tomcat-coyotemaven | >=8.5.35,<=8.5.100 | Not reported |
| org.apache.tomcat:tomcat-coyotemaven | >=7.0.92,<=7.0.109 | Not reported |
| org.apache.tomcat:tomcat-coyotemaven | >=11.0.0-M1,<11.0.0-M21 | 11.0.0-M21 |
| org.apache.tomcat:tomcat-coyotemaven | >=10.1.0-M1,<10.1.25 | 10.1.25 |
| org.apache.tomcat:tomcat-coyotemaven | >=9.0.13,<9.0.90 | 9.0.90 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard| Package | Affected range | Fixed version |
|---|---|---|
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=11.0.0-M1,<11.0.0-M21 | 11.0.0-M21 |
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=10.1.0-M1,<10.1.25 | 10.1.25 |
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=9.0.13,<9.0.90 | 9.0.90 |
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=8.5.35,<=8.5.100 | Not reported |
| org.apache.tomcat.embed:tomcat-embed-coremaven | >=7.0.92,<=7.0.109 | Not reported |
| org.apache.tomcat:tomcat-coyotemaven | >=8.5.35,<=8.5.100 | Not reported |
| org.apache.tomcat:tomcat-coyotemaven | >=7.0.92,<=7.0.109 | Not reported |
| org.apache.tomcat:tomcat-coyotemaven | >=11.0.0-M1,<11.0.0-M21 | 11.0.0-M21 |
| org.apache.tomcat:tomcat-coyotemaven | >=10.1.0-M1,<10.1.25 | 10.1.25 |
| org.apache.tomcat:tomcat-coyotemaven | >=9.0.13,<9.0.90 | 9.0.90 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard