{"id":"CVE-2020-13934","title":"An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2","summary":"An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemor…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-401","CWE-476"],"vendor":"apache","product":"tomcat","affected":["tomcat >= 8.5.1, <= 8.5.56","tomcat >= 9.0.1, <= 9.0.36","tomcat = 9.0.0","tomcat = 10.0.0","debian_linux = 9.0","debian_linux = 10.0","oncommand_system_manager >= 3.0.0, <= 3.1.3","leap = 15.1","leap = 15.2","ubuntu_linux = 20.04","agile_engineering_data_management = 6.2.1.0","agile_product_lifecycle_management = 9.3.3","agile_product_lifecycle_management = 9.3.5","agile_product_lifecycle_management = 9.3.6","communications_instant_messaging_server = 10.0.1.5.0","fmw_platform = 12.2.1.3.0","fmw_platform = 12.2.1.4.0","instantis_enterprisetrack = 17.1","instantis_enterprisetrack = 17.2","instantis_enterprisetrack = 17.3","managed_file_transfer = 12.2.1.3.0","managed_file_transfer = 12.2.1.4.0","mysql_enterprise_monitor <= 8.0.21","siebel_ui_framework <= 20.12","workload_manager = 12.2.0.1","workload_manager = 18c","workload_manager = 19c"],"published":"2020-07-14","updated":"2026-08-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-13934","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00084.html","label":"security@apache.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00088.html","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r61f411cf82488d6ec213063fc15feeeb88e31b0ca9c29652ee4f962e%40%3Cannounce.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/ra072b1f786e7d139e86f1d1145572e0ff71cef38a96d9c6f5362aac8%40%3Cdev.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/07/msg00017.html","label":"security@apache.org"},{"url":"https://security.netapp.com/advisory/ntap-20200724-0003/","label":"security@apache.org"},{"url":"https://usn.ubuntu.com/4596-1/","label":"security@apache.org"},{"url":"https://www.debian.org/security/2020/dsa-4727","label":"security@apache.org"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"security@apache.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00084.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00088.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r61f411cf82488d6ec213063fc15feeeb88e31b0ca9c29652ee4f962e%40%3Cannounce.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/ra072b1f786e7d139e86f1d1145572e0ff71cef38a96d9c6f5362aac8%40%3Cdev.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/07/msg00017.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20200724-0003/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4596-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2020/dsa-4727","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.64124,"epssPercentile":0.99191,"ingestedAt":"2026-08-25T17:29:30.185Z","slug":"CVE-2020-13934","body":"## Overview\n\nAn h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.\n\n## Affected\n\n- `tomcat >= 8.5.1, <= 8.5.56`\n- `tomcat >= 9.0.1, <= 9.0.36`\n- `tomcat = 9.0.0`\n- `tomcat = 10.0.0`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `oncommand_system_manager >= 3.0.0, <= 3.1.3`\n- `leap = 15.1`\n- `leap = 15.2`\n- `ubuntu_linux = 20.04`\n- `agile_engineering_data_management = 6.2.1.0`\n- `agile_product_lifecycle_management = 9.3.3`\n- `agile_product_lifecycle_management = 9.3.5`\n- `agile_product_lifecycle_management = 9.3.6`\n- `communications_instant_messaging_server = 10.0.1.5.0`\n- `fmw_platform = 12.2.1.3.0`\n- `fmw_platform = 12.2.1.4.0`\n- `instantis_enterprisetrack = 17.1`\n- `instantis_enterprisetrack = 17.2`\n- `instantis_enterprisetrack = 17.3`\n- `managed_file_transfer = 12.2.1.3.0`\n- `managed_file_transfer = 12.2.1.4.0`\n- `mysql_enterprise_monitor <= 8.0.21`\n- `siebel_ui_framework <= 20.12`\n- `workload_manager = 12.2.0.1`\n- `workload_manager = 18c`\n- `workload_manager = 19c`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":54,"depthScoreParts":{"impact":41.3,"likelihood":12.8,"exploitation":0,"ransomware":0},"changes":[]}