{"id":"CVE-2020-1935","title":"In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid","summary":"In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP…","severity":"medium","cvss":4.8,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N","cwe":["CWE-444"],"vendor":"apache","product":"tomcat","affected":["tomcat >= 7.0.0, <= 7.0.99","tomcat >= 8.5.0, <= 8.5.50","tomcat >= 9.0.0, <= 9.0.30","tomcat = 9.0.0","debian_linux = 8.0","debian_linux = 9.0","debian_linux = 10.0","ubuntu_linux = 16.04","leap = 15.1","data_availability_services","oncommand_system_manager >= 3.0.0, <= 3.1.3","agile_engineering_data_management = 6.2.1.0","agile_product_lifecycle_management = 9.3.3","agile_product_lifecycle_management = 9.3.5","agile_product_lifecycle_management = 9.3.6","communications_element_manager = 8.1.1","communications_element_manager = 8.2.0","communications_element_manager = 8.2.1","communications_instant_messaging_server = 10.0.1.4.0","health_sciences_empirica_inspections = 1.0.1.2","health_sciences_empirica_signal = 7.3.3","hospitality_guest_access = 4.2.0","hospitality_guest_access = 4.2.1","hyperion_infrastructure_technology = 11.1.2.4","instantis_enterprisetrack >= 17.1, <= 17.3","mysql_enterprise_monitor >= 4.0.0, <= 4.0.12","mysql_enterprise_monitor >= 8.0.0, <= 8.0.20","retail_order_broker = 15.0","siebel_ui_framework <= 20.5","transportation_management = 6.3.7","workload_manager = 12.2.0.1","workload_manager = 18c","workload_manager = 19c"],"published":"2020-02-24","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:24.610","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-1935","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r127f76181aceffea2bd4711b03c595d0f115f63e020348fe925a916c%40%3Cannounce.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r441c1f30a252bf14b07396286f6abd8089ce4240e91323211f1a2d75%40%3Cusers.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r660cd379afe346f10d72c0eaa8459ccc95d83aff181671b7e9076919%40%3Cusers.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r7bc994c965a34876bd94d5ff15b4e1e30b6220a15eb9b47c81915b78%40%3Ccommits.tomee.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r80e9c8417c77d52c62809168b96912bda70ddf7748f19f8210f745b1%40%3Cusers.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r9ce7918faf347e7aac32be930bf26c233b0b140fe37af0bb294158b6%40%3Cdev.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/ra5dee390ad2d60307b8362505c059cd6a726de4d146d63dfce1e05e7%40%3Cusers.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rc31cbabb46cdc58bbdd8519a8f64b6236b2635a3922bbeba0f0e3743%40%3Ccommits.tomee.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rd547be0c9d821b4b1000a694b8e58ef9f5e2d66db03a31dfe77c4b18%40%3Cusers.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html","label":"security@apache.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","label":"security@apache.org"},{"url":"https://security.netapp.com/advisory/ntap-20200327-0005/","label":"security@apache.org"},{"url":"https://usn.ubuntu.com/4448-1/","label":"security@apache.org"},{"url":"https://www.debian.org/security/2020/dsa-4673","label":"security@apache.org"},{"url":"https://www.debian.org/security/2020/dsa-4680","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"security@apache.org"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"security@apache.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00025.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r127f76181aceffea2bd4711b03c595d0f115f63e020348fe925a916c%40%3Cannounce.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r441c1f30a252bf14b07396286f6abd8089ce4240e91323211f1a2d75%40%3Cusers.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r660cd379afe346f10d72c0eaa8459ccc95d83aff181671b7e9076919%40%3Cusers.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r7bc994c965a34876bd94d5ff15b4e1e30b6220a15eb9b47c81915b78%40%3Ccommits.tomee.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r80e9c8417c77d52c62809168b96912bda70ddf7748f19f8210f745b1%40%3Cusers.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/r9ce7918faf347e7aac32be930bf26c233b0b140fe37af0bb294158b6%40%3Cdev.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/ra5dee390ad2d60307b8362505c059cd6a726de4d146d63dfce1e05e7%40%3Cusers.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rc31cbabb46cdc58bbdd8519a8f64b6236b2635a3922bbeba0f0e3743%40%3Ccommits.tomee.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rd547be0c9d821b4b1000a694b8e58ef9f5e2d66db03a31dfe77c4b18%40%3Cusers.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/03/msg00006.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/05/msg00026.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20200327-0005/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4448-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2020/dsa-4673","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2020/dsa-4680","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujan2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpujul2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2020.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.09386,"epssPercentile":0.95284,"ingestedAt":"2026-10-08T22:11:53.711Z","slug":"CVE-2020-1935","body":"## Overview\n\nIn Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.\n\n## Affected\n\n- `tomcat >= 7.0.0, <= 7.0.99`\n- `tomcat >= 8.5.0, <= 8.5.50`\n- `tomcat >= 9.0.0, <= 9.0.30`\n- `tomcat = 9.0.0`\n- `debian_linux = 8.0`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `ubuntu_linux = 16.04`\n- `leap = 15.1`\n- `data_availability_services`\n- `oncommand_system_manager >= 3.0.0, <= 3.1.3`\n- `agile_engineering_data_management = 6.2.1.0`\n- `agile_product_lifecycle_management = 9.3.3`\n- `agile_product_lifecycle_management = 9.3.5`\n- `agile_product_lifecycle_management = 9.3.6`\n- `communications_element_manager = 8.1.1`\n- `communications_element_manager = 8.2.0`\n- `communications_element_manager = 8.2.1`\n- `communications_instant_messaging_server = 10.0.1.4.0`\n- `health_sciences_empirica_inspections = 1.0.1.2`\n- `health_sciences_empirica_signal = 7.3.3`\n- `hospitality_guest_access = 4.2.0`\n- `hospitality_guest_access = 4.2.1`\n- `hyperion_infrastructure_technology = 11.1.2.4`\n- `instantis_enterprisetrack >= 17.1, <= 17.3`\n- `mysql_enterprise_monitor >= 4.0.0, <= 4.0.12`\n- `mysql_enterprise_monitor >= 8.0.0, <= 8.0.20`\n- `retail_order_broker = 15.0`\n- `siebel_ui_framework <= 20.5`\n- `transportation_management = 6.3.7`\n- `workload_manager = 12.2.0.1`\n- `workload_manager = 18c`\n- `workload_manager = 19c`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":26.4,"likelihood":1.9,"exploitation":0,"ransomware":0},"changes":[]}