Apache Tomcat does not enforce the maxHttpHeaderSize limit
High severity
GitHub Reviewed
Published
May 14, 2022
to the GitHub Advisory Database
•
Updated Feb 21, 2024
Package
Affected versions
>= 6.0.0, <= 6.0.30
>= 7.0.0, <= 7.0.6
Patched versions
6.0.32
7.0.8
Description
Published by the National Vulnerability Database
Feb 10, 2011
Published to the GitHub Advisory Database
May 14, 2022
Reviewed
Feb 21, 2024
Last updated
Feb 21, 2024
Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.
References