{"id":"CVE-2020-13935","title":"The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104","summary":"The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requ…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-835"],"vendor":"apache","product":"tomcat","affected":["tomcat >= 7.0.27, <= 7.0.104","tomcat >= 8.5.0, <= 8.5.56","tomcat >= 9.0.1, <= 9.0.36","tomcat = 9.0.0","tomcat = 10.0.0","debian_linux = 9.0","debian_linux = 10.0","oncommand_system_manager >= 3.0.0, <= 3.1.3","leap = 15.1","leap = 15.2","ubuntu_linux = 16.04","ubuntu_linux = 20.04","epolicy_orchestrator = 5.9.0","epolicy_orchestrator = 5.9.1","epolicy_orchestrator = 5.10.0","agile_engineering_data_management = 6.2.1.0","agile_product_lifecycle_management = 9.3.3","agile_product_lifecycle_management = 9.3.5","agile_product_lifecycle_management = 9.3.6","blockchain_platform < 21.1.2","commerce_guided_search = 11.3.2","communications_cloud_native_core_policy = 1.14.0","communications_instant_messaging_server = 10.0.1.5.0","fmw_platform = 12.2.1.3.0","fmw_platform = 12.2.1.4.0","instantis_enterprisetrack = 17.1","instantis_enterprisetrack = 17.2","instantis_enterprisetrack = 17.3","managed_file_transfer = 12.2.1.3.0","managed_file_transfer = 12.2.1.4.0","mysql_enterprise_monitor <= 8.0.21","siebel_ui_framework <= 20.12","workload_manager = 12.2.0.1","workload_manager = 18c","workload_manager = 19c"],"patched":["blockchain_platform 21.1.2"],"published":"2020-07-14","updated":"2026-08-25","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-13935","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00084.html","label":"security@apache.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00088.html","label":"security@apache.org"},{"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10332","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r4e5d3c09f4dd2923191e972408b40fb8b42dbff0bc7904d44b651e50%40%3Cusers.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rd48c72bd3255bda87564d4da3791517c074d94f8a701f93b85752651%40%3Cannounce.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/07/msg00017.html","label":"security@apache.org"},{"url":"https://security.netapp.com/advisory/ntap-20200724-0003/","label":"security@apache.org"},{"url":"https://usn.ubuntu.com/4448-1/","label":"security@apache.org"},{"url":"https://usn.ubuntu.com/4596-1/","label":"security@apache.org"},{"url":"https://www.debian.org/security/2020/dsa-4727","label":"security@apache.org"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"security@apache.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00084.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00088.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://kc.mcafee.com/corporate/index?page=content&id=SB10332","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r4e5d3c09f4dd2923191e972408b40fb8b42dbff0bc7904d44b651e50%40%3Cusers.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rd48c72bd3255bda87564d4da3791517c074d94f8a701f93b85752651%40%3Cannounce.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/07/msg00017.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20200724-0003/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4448-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4596-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2020/dsa-4727","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.86608,"epssPercentile":0.99736,"ingestedAt":"2026-08-25T17:29:30.225Z","exploits":{"github":2,"githubRepos":["https://github.com/RedTeamPentesting/CVE-2020-13935","https://github.com/aabbcc19191/CVE-2020-13935"],"checkedAt":"2026-09-21T15:23:47.830Z"},"exploitAvailable":true,"slug":"CVE-2020-13935","body":"## Overview\n\nThe payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.\n\n## Affected\n\n- `tomcat >= 7.0.27, <= 7.0.104`\n- `tomcat >= 8.5.0, <= 8.5.56`\n- `tomcat >= 9.0.1, <= 9.0.36`\n- `tomcat = 9.0.0`\n- `tomcat = 10.0.0`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `oncommand_system_manager >= 3.0.0, <= 3.1.3`\n- `leap = 15.1`\n- `leap = 15.2`\n- `ubuntu_linux = 16.04`\n- `ubuntu_linux = 20.04`\n- `epolicy_orchestrator = 5.9.0`\n- `epolicy_orchestrator = 5.9.1`\n- `epolicy_orchestrator = 5.10.0`\n- `agile_engineering_data_management = 6.2.1.0`\n- `agile_product_lifecycle_management = 9.3.3`\n- `agile_product_lifecycle_management = 9.3.5`\n- `agile_product_lifecycle_management = 9.3.6`\n- `blockchain_platform < 21.1.2`\n- `commerce_guided_search = 11.3.2`\n- `communications_cloud_native_core_policy = 1.14.0`\n- `communications_instant_messaging_server = 10.0.1.5.0`\n- `fmw_platform = 12.2.1.3.0`\n- `fmw_platform = 12.2.1.4.0`\n- `instantis_enterprisetrack = 17.1`\n- `instantis_enterprisetrack = 17.2`\n- `instantis_enterprisetrack = 17.3`\n- `managed_file_transfer = 12.2.1.3.0`\n- `managed_file_transfer = 12.2.1.4.0`\n- `mysql_enterprise_monitor <= 8.0.21`\n- `siebel_ui_framework <= 20.12`\n- `workload_manager = 12.2.0.1`\n- `workload_manager = 18c`\n- `workload_manager = 19c`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `blockchain_platform 21.1.2`","depth":"midnight","depthScore":71,"depthScoreParts":{"impact":41.3,"likelihood":17.3,"exploitation":12,"ransomware":0},"changes":[{"seq":4472,"id":"CVE-2020-13935","ts":1788887182359,"field":"exploit_available","old":"false","new":"true"},{"seq":3355,"id":"CVE-2020-13935","ts":1788886301356,"field":"exploit_available","old":"true","new":"false"},{"seq":2210,"id":"CVE-2020-13935","ts":1788882971089,"field":"exploit_available","old":"false","new":"true"},{"seq":1239,"id":"CVE-2020-13935","ts":1788882382640,"field":"exploit_available","old":"true","new":"false"},{"seq":353,"id":"CVE-2020-13935","ts":1788881817309,"field":"exploit_available","old":"false","new":"true"}]}