{"id":"CVE-2020-13943","title":"If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possibl…","summary":"If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possibl…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","vendor":"apache","product":"tomcat","affected":["tomcat = 8.5.0","tomcat = 8.5.1","tomcat = 8.5.2","tomcat = 8.5.3","tomcat = 8.5.4","tomcat = 8.5.5","tomcat = 8.5.6","tomcat = 8.5.7","tomcat = 8.5.8","tomcat = 8.5.9","tomcat = 8.5.10","tomcat = 8.5.11","tomcat = 8.5.12","tomcat = 8.5.13","tomcat = 8.5.14","tomcat = 8.5.15","tomcat = 8.5.16","tomcat = 8.5.17","tomcat = 8.5.18","tomcat = 8.5.19","tomcat = 8.5.20","tomcat = 8.5.21","tomcat = 8.5.22","tomcat = 8.5.23","tomcat = 8.5.24","tomcat = 8.5.25","tomcat = 8.5.26","tomcat = 8.5.27","tomcat = 8.5.28","tomcat = 8.5.29","tomcat = 8.5.30","tomcat = 8.5.31","tomcat = 8.5.32","tomcat = 8.5.33","tomcat = 8.5.34","tomcat = 8.5.35","tomcat = 8.5.36","tomcat = 8.5.37","tomcat = 8.5.38","tomcat = 8.5.39","tomcat = 8.5.40","tomcat = 8.5.41","tomcat = 8.5.42","tomcat = 8.5.43","tomcat = 8.5.44","tomcat = 8.5.45","tomcat = 8.5.46","tomcat = 8.5.47","tomcat = 8.5.48","tomcat = 8.5.49","tomcat = 8.5.50","tomcat = 8.5.51","tomcat = 8.5.52","tomcat = 8.5.53","tomcat = 8.5.54","tomcat = 8.5.55","tomcat = 8.5.56","tomcat = 8.5.57","tomcat = 9.0.0","tomcat = 9.0.1","tomcat = 9.0.2","tomcat = 9.0.3","tomcat = 9.0.4","tomcat = 9.0.5","tomcat = 9.0.6","tomcat = 9.0.7","tomcat = 9.0.8","tomcat = 9.0.9","tomcat = 9.0.10","tomcat = 9.0.11","tomcat = 9.0.12","tomcat = 9.0.13","tomcat = 9.0.14","tomcat = 9.0.15","tomcat = 9.0.16","tomcat = 9.0.17","tomcat = 9.0.18","tomcat = 9.0.19","tomcat = 9.0.20","tomcat = 9.0.21","tomcat = 9.0.22","tomcat = 9.0.23","tomcat = 9.0.24","tomcat = 9.0.25","tomcat = 9.0.26","tomcat = 9.0.27","tomcat = 9.0.28","tomcat = 9.0.29","tomcat = 9.0.30","tomcat = 9.0.31","tomcat = 9.0.32","tomcat = 9.0.33","tomcat = 9.0.34","tomcat = 9.0.35","tomcat = 9.0.36","tomcat = 9.0.37","tomcat = 10.0.0","debian_linux = 9.0","debian_linux = 10.0","instantis_enterprisetrack = 17.1"],"published":"2020-10-12","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:16:56.900","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-13943","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00002.html","label":"security@apache.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00021.html","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r4a390027eb27e4550142fac6c8317cc684b157ae314d31514747f307%40%3Cannounce.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/10/msg00019.html","label":"security@apache.org"},{"url":"https://security.netapp.com/advisory/ntap-20201016-0007/","label":"security@apache.org"},{"url":"https://www.debian.org/security/2021/dsa-4835","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"security@apache.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00002.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r4a390027eb27e4550142fac6c8317cc684b157ae314d31514747f307%40%3Cannounce.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/10/msg00019.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20201016-0007/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2021/dsa-4835","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuApr2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.54966,"epssPercentile":0.99005,"ingestedAt":"2026-10-08T23:16:47.309Z","slug":"CVE-2020-13943","body":"## Overview\n\nIf an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.\n\n## Affected\n\n- `tomcat = 8.5.0`\n- `tomcat = 8.5.1`\n- `tomcat = 8.5.2`\n- `tomcat = 8.5.3`\n- `tomcat = 8.5.4`\n- `tomcat = 8.5.5`\n- `tomcat = 8.5.6`\n- `tomcat = 8.5.7`\n- `tomcat = 8.5.8`\n- `tomcat = 8.5.9`\n- `tomcat = 8.5.10`\n- `tomcat = 8.5.11`\n- `tomcat = 8.5.12`\n- `tomcat = 8.5.13`\n- `tomcat = 8.5.14`\n- `tomcat = 8.5.15`\n- `tomcat = 8.5.16`\n- `tomcat = 8.5.17`\n- `tomcat = 8.5.18`\n- `tomcat = 8.5.19`\n- `tomcat = 8.5.20`\n- `tomcat = 8.5.21`\n- `tomcat = 8.5.22`\n- `tomcat = 8.5.23`\n- `tomcat = 8.5.24`\n- `tomcat = 8.5.25`\n- `tomcat = 8.5.26`\n- `tomcat = 8.5.27`\n- `tomcat = 8.5.28`\n- `tomcat = 8.5.29`\n- `tomcat = 8.5.30`\n- `tomcat = 8.5.31`\n- `tomcat = 8.5.32`\n- `tomcat = 8.5.33`\n- `tomcat = 8.5.34`\n- `tomcat = 8.5.35`\n- `tomcat = 8.5.36`\n- `tomcat = 8.5.37`\n- `tomcat = 8.5.38`\n- `tomcat = 8.5.39`\n- `tomcat = 8.5.40`\n- `tomcat = 8.5.41`\n- `tomcat = 8.5.42`\n- `tomcat = 8.5.43`\n- `tomcat = 8.5.44`\n- `tomcat = 8.5.45`\n- `tomcat = 8.5.46`\n- `tomcat = 8.5.47`\n- `tomcat = 8.5.48`\n- `tomcat = 8.5.49`\n- `tomcat = 8.5.50`\n- `tomcat = 8.5.51`\n- `tomcat = 8.5.52`\n- `tomcat = 8.5.53`\n- `tomcat = 8.5.54`\n- `tomcat = 8.5.55`\n- `tomcat = 8.5.56`\n- `tomcat = 8.5.57`\n- `tomcat = 9.0.0`\n- `tomcat = 9.0.1`\n- `tomcat = 9.0.2`\n- `tomcat = 9.0.3`\n- `tomcat = 9.0.4`\n- `tomcat = 9.0.5`\n- `tomcat = 9.0.6`\n- `tomcat = 9.0.7`\n- `tomcat = 9.0.8`\n- `tomcat = 9.0.9`\n- `tomcat = 9.0.10`\n- `tomcat = 9.0.11`\n- `tomcat = 9.0.12`\n- `tomcat = 9.0.13`\n- `tomcat = 9.0.14`\n- `tomcat = 9.0.15`\n- `tomcat = 9.0.16`\n- `tomcat = 9.0.17`\n- `tomcat = 9.0.18`\n- `tomcat = 9.0.19`\n- `tomcat = 9.0.20`\n- `tomcat = 9.0.21`\n- `tomcat = 9.0.22`\n- `tomcat = 9.0.23`\n- `tomcat = 9.0.24`\n- `tomcat = 9.0.25`\n- `tomcat = 9.0.26`\n- `tomcat = 9.0.27`\n- `tomcat = 9.0.28`\n- `tomcat = 9.0.29`\n- `tomcat = 9.0.30`\n- `tomcat = 9.0.31`\n- `tomcat = 9.0.32`\n- `tomcat = 9.0.33`\n- `tomcat = 9.0.34`\n- `tomcat = 9.0.35`\n- `tomcat = 9.0.36`\n- `tomcat = 9.0.37`\n- `tomcat = 10.0.0`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `instantis_enterprisetrack = 17.1`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":23.7,"likelihood":11,"exploitation":0,"ransomware":0},"changes":[]}