Response mix-up with WebSocket concurrent send and close
Published May 13, 2022
8.6
HIGHCVSS 3.1
EPSS 8.40%
Description
If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to be placed in the pool twice. This could result in subsequent connections using the same object concurrently which could result in data being returned to the wrong use and/or other errors.
Affected products
-
- Version Apache Tomcat 8.5 8.5.0 to 8.5.75StatusaffectedConstraints-
- Version Apache Tomcat 9 9.0.0.M1 to 9.0.20StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Tomcat | n/a |
|
No data.
Red Hat Enterprise Linux 8
pki-core:10.6-8030020200911215836.5ff1562f
Fixed · RHSA-2020:4847
Red Hat Enterprise Linux 8
pki-deps:10.6-8030020200527165326.30b713e6
Fixed · RHSA-2020:4847
Red Hat Enterprise Linux 6
tomcat6
Out of support scope
Red Hat Enterprise Linux 7
tomcat
Not affected
Red Hat Enterprise Linux 9
pki-servlet-engine
Not affected
Red Hat JBoss Web Server 3
tomcat
Not affected
Red Hat JBoss Web Server 5
tomcat
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 8 | pki-core:10.6-8030020200911215836.5ff1562f | Fixed | RHSA-2020:4847 |
| Red Hat Enterprise Linux 8 | pki-deps:10.6-8030020200527165326.30b713e6 | Fixed | RHSA-2020:4847 |
| Red Hat Enterprise Linux 6 | tomcat6 | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | tomcat | Not affected | n/a |
| Red Hat Enterprise Linux 9 | pki-servlet-engine | Not affected | n/a |
| Red Hat JBoss Web Server 3 | tomcat | Not affected | n/a |
| Red Hat JBoss Web Server 5 | tomcat | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (22 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 8.40% (0.08405) | 94.82th | v5 (v2026.06.15) |
| Jun 15, 2026 | 7.54% (0.07538) | 93.71th | v5 (v2026.06.15) |
| Nov 21, 2025 | 0.55% (0.00552) | 67.13th | v4 (v2025.03.14) |
| Nov 18, 2025 | 5.87% (0.05872) | 89.64th | v4 (v2025.03.14) |
| Mar 30, 2025 | 0.33% (0.00326) | 52.52th | v4 (v2025.03.14) |
| Mar 29, 2025 | 7.57% (0.07571) | 86.12th | v4 (v2025.03.14) |
| Mar 24, 2025 | 0.33% (0.00326) | 52.59th | v4 (v2025.03.14) |
| Mar 23, 2025 | 2.95% (0.02949) | 83.93th | v4 (v2025.03.14) |
| Mar 17, 2025 | 0.33% (0.00326) | 53.35th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.61% (0.00606) | 79.27th | v3 (v2023.03.01) |
| Mar 14, 2024 | 0.61% (0.00606) | 78.08th | v3 (v2023.03.01) |
| Dec 4, 2023 | 0.61% (0.00606) | 76.07th | v3 (v2023.03.01) |
| Oct 24, 2023 | 0.86% (0.00858) | 80.38th | v3 (v2023.03.01) |
| Sep 27, 2023 | 0.62% (0.00624) | 76.41th | v3 (v2023.03.01) |
| Jun 15, 2023 | 0.62% (0.00617) | 75.82th | v3 (v2023.03.01) |
| May 20, 2023 | 0.63% (0.00630) | 75.96th | v3 (v2023.03.01) |
| May 9, 2023 | 0.28% (0.00283) | 63.84th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.20% (0.00202) | 56.31th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00954) | 36.37th | v2 (v2022.01.01) |
| Feb 22, 2023 | 0.95% (0.00954) | 36.13th | v2 (v2022.01.01) |
| Jul 26, 2022 | 0.95% (0.00954) | 34.06th | v2 (v2022.01.01) |
| May 13, 2022 | 0.89% (0.00885) | 24.79th | v2 (v2022.01.01) |
References (9)
- https://access.redhat.com/security/cve/CVE-2022-25762 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2085304 Issue Tracking
- https://github.com/advisories/GHSA-h3ch-5pp2-vh6w Advisory
- https://lists.apache.org/thread/6ckmjfb1k61dyzkto9vm2k5jvt4o7w7c x_refsource_MISCMailing ListVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2022-25762
- https://security.netapp.com/advisory/ntap-20220629-0003/ x_refsource_CONFIRMThird Party Advisory
- https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.76
- https://www.cve.org/CVERecord?id=CVE-2022-25762
- https://www.oracle.com/security-alerts/cpujul2022.html x_refsource_MISCPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2022-25762 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2085304 | Issue Tracking | |
| https://github.com/advisories/GHSA-h3ch-5pp2-vh6w | Advisory | |
| https://lists.apache.org/thread/6ckmjfb1k61dyzkto9vm2k5jvt4o7w7c | x_refsource_MISCMailing ListVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2022-25762 | ||
| https://security.netapp.com/advisory/ntap-20220629-0003/ | x_refsource_CONFIRMThird Party Advisory | |
| https://tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.76 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-25762 | ||
| https://www.oracle.com/security-alerts/cpujul2022.html | x_refsource_MISCPatchThird Party Advisory |
Change history (0)
No recorded changes yet.