{"id":"CVE-2021-41079","title":"Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets","summary":"Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to …","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-20","CWE-835"],"vendor":"apache","product":"tomcat","affected":["tomcat >= 8.5.0, < 8.5.64","tomcat >= 9.0.0, < 9.0.44","tomcat >= 10.0.0, <= 10.0.2","debian_linux = 9.0","debian_linux = 10.0","debian_linux = 11.0","management_services_for_element_software_and_netapp_hci"],"patched":["tomcat 9.0.44"],"published":"2021-09-16","updated":"2026-10-08","sourceUpdated":"2026-10-08T22:17:12.473","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-41079","references":[{"url":"https://lists.apache.org/thread.html/r6b6b674e3f168dd010e67dbe6848b866e2acf26371452fdae313b98a%40%3Cusers.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rb4de81ac647043541a32881099aa6eb5a23f1b7fd116f713f8ab9dbe%40%3Cdev.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/rccdef0349fdf4fb73a4e4403095446d7fe6264e0a58e2df5c6799434%40%3Cannounce.tomcat.apache.org%3E","label":"security@apache.org"},{"url":"https://lists.debian.org/debian-lts-announce/2021/09/msg00012.html","label":"security@apache.org"},{"url":"https://security.netapp.com/advisory/ntap-20211008-0005/","label":"security@apache.org"},{"url":"https://www.debian.org/security/2021/dsa-4986","label":"security@apache.org"},{"url":"https://lists.apache.org/thread.html/r6b6b674e3f168dd010e67dbe6848b866e2acf26371452fdae313b98a%40%3Cusers.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rb4de81ac647043541a32881099aa6eb5a23f1b7fd116f713f8ab9dbe%40%3Cdev.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rccdef0349fdf4fb73a4e4403095446d7fe6264e0a58e2df5c6799434%40%3Cannounce.tomcat.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2021/09/msg00012.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20211008-0005/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.debian.org/security/2021/dsa-4986","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.07182,"epssPercentile":0.94146,"ingestedAt":"2026-10-08T23:16:47.322Z","slug":"CVE-2021-41079","body":"## Overview\n\nApache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.\n\n## Affected\n\n- `tomcat >= 8.5.0, < 8.5.64`\n- `tomcat >= 9.0.0, < 9.0.44`\n- `tomcat >= 10.0.0, <= 10.0.2`\n- `debian_linux = 9.0`\n- `debian_linux = 10.0`\n- `debian_linux = 11.0`\n- `management_services_for_element_software_and_netapp_hci`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `tomcat 9.0.44`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":41.3,"likelihood":1.4,"exploitation":0,"ransomware":0},"changes":[]}