A AegiFlow
HIGHCVSS 7.5EPSS 86.6%

CVE-2020-13935

CVE-2020-13935 updated by NVD

Published
2022-02-08
Modified
2026-08-27
EPSS percentile
100%
Sources
github-advisory, nvd

Summary

The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.apache.tomcat.embed:tomcat-embed-websocket7.0.105, 8.5.57, 9.0.37, 10.0.0-M7
Mavenorg.apache.tomcat:tomcat10.0.0-M7, 9.0.37, 8.5.57, 7.0.105
Mavenorg.apache.tomcat:tomcat-websocket10.0.0-M7, 9.0.37, 8.5.57, 7.0.105

Remediation: Upgrade to 7.0.105 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.