Apache Tomcat DoS via Memory Leak in HTTP Priority Header Parsing (v9-10, v11)
CVE-2025-31650 Published on April 28, 2025
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service.
This issue affects Apache Tomcat: from 9.0.76 through 9.0.102, from 10.1.10 through 10.1.39, from 11.0.0-M2 through 11.0.5.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.90 though 8.5.100.
Users are recommended to upgrade to version 9.0.104, 10.1.40 or 11.0.6 which fix the issue.
Vulnerability Analysis
CVE-2025-31650 is exploitable with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Type
What is an Insufficient Cleanup Vulnerability?
The software does not properly "clean up" and remove temporary or supporting resources after they have been used.
CVE-2025-31650 has been classified to as an Insufficient Cleanup vulnerability or weakness.
Products Associated with CVE-2025-31650
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2025-31650 are published in these products:
Affected Versions
Apache Software Foundation Apache Tomcat:- Version 9.0.76, <= 9.0.102 is affected.
- Version 10.1.10, <= 10.1.39 is affected.
- Version 11.0.0-M2, <= 11.0.5 is affected.
- Version 8.5.90, <= 8.5.100 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.