GHSA-767j-jfh2-jvrc · Severity: medium · Ecosystem: maven — Potential HTTP request smuggling in Apache Tomcat
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
Conclusion & alert: CVE-2019-17569 is rated Moderate Risk (55/100): CVSS Medium severity, with high exploitation likelihood (EPSS 8.87%, 95th percentile). Core evidence: EPSS ranks this CVE among the most likely to be exploited in the near term. EPSS rose +2.71% over the last day, indicating growing attacker interest. Mandatory action: High exploitation likelihood—assess exposure and prioritize remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 6.16% | 8.87% | +2.71% |
| 2 | 2026-03-28 | 6.06% | 6.16% | +0.10% |
| 3 | 2026-03-04 | — | 6.06% | — |
Full EPSS history (40 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 4.8 | 3.1 | MEDIUM |
|
2.2 | 2.5 | [email protected] |
| 5.8 | 2.0 | MEDIUM |
|
8.6 | 4.9 | [email protected] |
GHSA-767j-jfh2-jvrc · Severity: medium · Ecosystem: maven — Potential HTTP request smuggling in Apache Tomcat
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2019-17569 not yet assigned priority: Debian including 1 source packages (tomcat9), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2019-17569 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2019-17569 |
ubuntu
|
low | CVE-2019-17569 low priority: Ubuntu including 3 source packages (tomcat7, tomcat8, tomcat9), 15 status rows across 5 suites (bionic, eoan, trusty, upstream, xenial): not-affected 7, DNE 5, needs-triage 2, released 1. | https://ubuntu.com/security/CVE-2019-17569 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| apache | tomcat | >= 7.0.98, <= 7.0.99 | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* |
| apache | tomcat | >= 8.5.48, <= 8.5.50 | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* |
| apache | tomcat | >= 9.0.28, <= 9.0.30 | cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* |
| apache | tomee | 7.0.7 | cpe:2.3:a:apache:tomee:7.0.7:*:*:*:*:*:*:* |
| opensuse | leap | 15.1 | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
| netapp | data_availability_services | — | cpe:2.3:a:netapp:data_availability_services:-:*:*:*:*:*:*:* |
| netapp | oncommand_system_manager | >= 3.0.0, <= 3.1.3 | cpe:2.3:a:netapp:oncommand_system_manager:*:*:*:*:*:*:*:* |
| debian | debian_linux | 9.0 | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
| debian | debian_linux | 10.0 | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
| oracle | agile_engineering_data_management | 6.2.1.0 | cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:* |
| oracle | agile_plm | 9.3.3 | cpe:2.3:a:oracle:agile_plm:9.3.3:*:*:*:*:*:*:* |
| oracle | agile_plm | 9.3.5 | cpe:2.3:a:oracle:agile_plm:9.3.5:*:*:*:*:*:*:* |
| oracle | agile_plm | 9.3.6 | cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:* |
| oracle | communications_instant_messaging_server | 10.0.1.4.0 | cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.4.0:*:*:*:*:*:*:* |
| oracle | health_sciences_empirica_inspections | 1.0.1.2 | cpe:2.3:a:oracle:health_sciences_empirica_inspections:1.0.1.2:*:*:*:*:*:*:* |
| oracle | health_sciences_empirica_signal | 7.3.3 | cpe:2.3:a:oracle:health_sciences_empirica_signal:7.3.3:*:*:*:*:*:*:* |
| oracle | hospitality_guest_access | 4.2.0 | cpe:2.3:a:oracle:hospitality_guest_access:4.2.0:*:*:*:*:*:*:* |
| oracle | hospitality_guest_access | 4.2.1 | cpe:2.3:a:oracle:hospitality_guest_access:4.2.1:*:*:*:*:*:*:* |
| oracle | instantis_enterprisetrack | >= 17.1, <= 17.3 | cpe:2.3:a:oracle:instantis_enterprisetrack:*:*:*:*:*:*:*:* |
| oracle | mysql_enterprise_monitor | <= 4.0.12 | cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* |
| oracle | mysql_enterprise_monitor | >= 8.0.0, <= 8.0.20 | cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:* |
| oracle | transportation_management | 6.3.7 | cpe:2.3:a:oracle:transportation_management:6.3.7:*:*:*:*:*:*:* |
| oracle | workload_manager | 12.2.0.1 | cpe:2.3:a:oracle:workload_manager:12.2.0.1:*:*:*:*:*:*:* |
| oracle | workload_manager | 18c | cpe:2.3:a:oracle:workload_manager:18c:*:*:*:*:*:*:* |
| oracle | workload_manager | 19c | cpe:2.3:a:oracle:workload_manager:19c:*:*:*:*:*:*:* |