Back

HIGH

tomcat: OutOfMemoryException caused by HTTP/2 connection leak could lead to DoS

Published Jul 14, 2020

Description

An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.

Affected products

Remediation

Red Hat statement

Red Hat Certificate System 10.0 and Red Hat Enterprise Linux 8's Identity Management, are using a vulnerable version of Tomcat that is bundled into the pki-servlet-engine component. However, HTTP/2 is not enabled in such a configuration, and it is not possible to trigger the flaw in a supported setup. A future update may fix the code.

Metrics

References (24)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Jul 14, 2020
Updated Aug 4, 2024
Reserved Jun 8, 2020
NVD
Status Modified
Modified Aug 25, 2026
Red Hat
Severity Important
Public date Jul 15, 2020
GHSA-VF77-8H7G-GGHP