Apache Tomcat Vulnerable to Denial of Service (DoS) via Improper Handling of chunk extensions

Description

Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.

Basic information

Type
reviewed
Severity
medium
Advisory on GitHub
Open advisory ↗
Repository advisory
Source code
Browse source ↗
Published (advisory)
2022-05-14 01:10:36 UTC
Updated
2025-04-12 00:09:10 UTC
GitHub reviewed
2025-04-12 00:09:07 UTC
NVD published
2013-06-01

EPSS Score

Score Percentile
44.77% 97.52%

CVSS Scores

No CVSS scores in this advisory.

Identifiers

CWEs

CWE id Name
CWE-20 Improper Input Validation

Affected packages (2)

Vulnerable version ranges and first patched releases as published by GitHub.

Ecosystem Package Vulnerable range First patched Vulnerable functions
maven org.apache.tomcat:tomcat >= 6.0.0, < 6.0.37 6.0.37
maven org.apache.tomcat:tomcat >= 7.0.0, < 7.0.30 7.0.30

References

cvelogic Threat Intelligence