CVE Vulnerabilities

CVE-2025-31650

Incomplete Cleanup

Published: Apr 28, 2025 | Modified: Nov 03, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service.

This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.90 though 8.5.100.

Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue.

Weakness

The product does not properly “clean up” and remove temporary or supporting resources after they have been used.

Affected Software

NameVendorStart VersionEnd Version
TomcatApache9.0.76 (including)9.0.104 (excluding)
TomcatApache10.1.10 (including)10.1.40 (excluding)
TomcatApache11.0.1 (including)11.0.6 (excluding)
TomcatApache11.0.0-milestone10 (including)11.0.0-milestone10 (including)
TomcatApache11.0.0-milestone11 (including)11.0.0-milestone11 (including)
TomcatApache11.0.0-milestone12 (including)11.0.0-milestone12 (including)
TomcatApache11.0.0-milestone13 (including)11.0.0-milestone13 (including)
TomcatApache11.0.0-milestone14 (including)11.0.0-milestone14 (including)
TomcatApache11.0.0-milestone15 (including)11.0.0-milestone15 (including)
TomcatApache11.0.0-milestone16 (including)11.0.0-milestone16 (including)
TomcatApache11.0.0-milestone17 (including)11.0.0-milestone17 (including)
TomcatApache11.0.0-milestone18 (including)11.0.0-milestone18 (including)
TomcatApache11.0.0-milestone19 (including)11.0.0-milestone19 (including)
TomcatApache11.0.0-milestone2 (including)11.0.0-milestone2 (including)
TomcatApache11.0.0-milestone20 (including)11.0.0-milestone20 (including)
TomcatApache11.0.0-milestone21 (including)11.0.0-milestone21 (including)
TomcatApache11.0.0-milestone22 (including)11.0.0-milestone22 (including)
TomcatApache11.0.0-milestone23 (including)11.0.0-milestone23 (including)
TomcatApache11.0.0-milestone24 (including)11.0.0-milestone24 (including)
TomcatApache11.0.0-milestone25 (including)11.0.0-milestone25 (including)
TomcatApache11.0.0-milestone3 (including)11.0.0-milestone3 (including)
TomcatApache11.0.0-milestone4 (including)11.0.0-milestone4 (including)
TomcatApache11.0.0-milestone5 (including)11.0.0-milestone5 (including)
TomcatApache11.0.0-milestone6 (including)11.0.0-milestone6 (including)
TomcatApache11.0.0-milestone7 (including)11.0.0-milestone7 (including)
TomcatApache11.0.0-milestone8 (including)11.0.0-milestone8 (including)
TomcatApache11.0.0-milestone9 (including)11.0.0-milestone9 (including)
Red Hat Enterprise Linux 10RedHattomcat9-1:9.0.87-5.el10_0.1*
Red Hat Enterprise Linux 8RedHattomcat-1:9.0.87-1.el8_10.4*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHattomcat-1:9.0.87-1.el8_8.5*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHattomcat-1:9.0.87-1.el8_8.5*
Red Hat Enterprise Linux 9RedHattomcat-1:9.0.87-3.el9_6.1*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHattomcat-1:9.0.87-1.el9_2.4*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHattomcat-1:9.0.87-1.el9_4.4*
Red Hat JBoss Web Server 5RedHattomcat*
Red Hat JBoss Web Server 5.8 on RHEL 7RedHatjws5-tomcat-0:9.0.87-11.redhat_00010.1.el7jws*
Red Hat JBoss Web Server 5.8 on RHEL 8RedHatjws5-tomcat-0:9.0.87-11.redhat_00010.1.el8jws*
Red Hat JBoss Web Server 5.8 on RHEL 9RedHatjws5-tomcat-0:9.0.87-11.redhat_00010.1.el9jws*
Red Hat JBoss Web Server 6RedHattomcat*
Red Hat JBoss Web Server 6.1 on RHEL 8RedHatjws6-tomcat-0:10.1.36-6.redhat_00007.1.el8jws*
Red Hat JBoss Web Server 6.1 on RHEL 8RedHatjws6-tomcat-jakartaee-migration-0:1.0.6-2.redhat_00003.1.el8jws*
Red Hat JBoss Web Server 6.1 on RHEL 8RedHatjws6-tomcat-native-0:1.3.1-1.redhat_1.el8jws*
Red Hat JBoss Web Server 6.1 on RHEL 9RedHatjws6-tomcat-0:10.1.36-6.redhat_00007.1.el9jws*
Red Hat JBoss Web Server 6.1 on RHEL 9RedHatjws6-tomcat-jakartaee-migration-0:1.0.6-2.redhat_00003.1.el9jws*
Red Hat JBoss Web Server 6.1 on RHEL 9RedHatjws6-tomcat-native-0:1.3.1-1.redhat_1.el9jws*
Tomcat10Ubuntuesm-apps/noble*
Tomcat10Ubuntunoble*
Tomcat10Ubuntuoracular*
Tomcat10Ubuntuupstream*
Tomcat8Ubuntuupstream*
Tomcat9Ubuntufocal*
Tomcat9Ubuntuupstream*

Potential Mitigations

References