GHSA-227g-7cvv-6ff3 · Severity: high · Ecosystem: maven — Apache Tapestry 5.8.1 vulnerable to ReDoS via Content Types causing catastrophic backtracking
Apache Tapestry up to version 5.8.1 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles Content Types. Specially crafted Content Types may cause catastrophic backtracking, taking exponential time to complete. Specifically, this is about the regular expression used on the parameter of the org.apache.tapestry5.http.ContentType class. Apache Tapestry 5.8.2 has a fix for this vulnerability. Notice the vulnerability cannot be triggered by web requests in Tapestry code alone. It would only happen if there's some non-Tapestry codepath passing some outside input to the ContentType class constructor.
Conclusion & alert: CVE-2022-31781 is rated Moderate Risk (56.7/100): CVSS High severity, with medium exploitation likelihood (EPSS 1.69%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.95% | 1.69% | +0.74% |
| 2 | 2026-06-11 | 0.76% | 0.95% | +0.19% |
| 3 | 2026-05-18 | — | 0.76% | — |
Full EPSS history (22 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
GHSA-227g-7cvv-6ff3 · Severity: high · Ecosystem: maven — Apache Tapestry 5.8.1 vulnerable to ReDoS via Content Types causing catastrophic backtracking
| URL | Tags |
|---|---|
| https://www.openwall.com/lists/oss-security/2022/07/12/3 | Mailing List Vendor Advisory |