A AegiFlow
HIGHCVSS 7.5EPSS 18.1%

CVE-2021-25122

CVE-2021-25122 updated by NVD

Published
2021-06-16
Modified
2026-08-27
EPSS percentile
97%
Sources
github-advisory, nvd

Summary

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.apache.tomcat.embed:tomcat-embed-core8.5.63, 10.0.2, 9.0.43
Mavenorg.apache.tomcat:tomcat-coyote10.0.2

Remediation: Upgrade to 8.5.63 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.