---
id: CVE-2021-41079
title: >-
  Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did
  not properly validate incoming TLS packets
summary: >-
  Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did
  not properly validate incoming TLS packets. When Tomcat was configured to use
  NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used
  to …
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-20
  - CWE-835
vendor: apache
product: tomcat
affected:
  - 'tomcat >= 8.5.0, < 8.5.64'
  - 'tomcat >= 9.0.0, < 9.0.44'
  - 'tomcat >= 10.0.0, <= 10.0.2'
  - debian_linux = 9.0
  - debian_linux = 10.0
  - debian_linux = 11.0
  - management_services_for_element_software_and_netapp_hci
patched:
  - tomcat 9.0.44
published: '2021-09-16'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:17:12.473'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-41079'
references:
  - url: >-
      https://lists.apache.org/thread.html/r6b6b674e3f168dd010e67dbe6848b866e2acf26371452fdae313b98a%40%3Cusers.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rb4de81ac647043541a32881099aa6eb5a23f1b7fd116f713f8ab9dbe%40%3Cdev.tomcat.apache.org%3E
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/rccdef0349fdf4fb73a4e4403095446d7fe6264e0a58e2df5c6799434%40%3Cannounce.tomcat.apache.org%3E
    label: security@apache.org
  - url: 'https://lists.debian.org/debian-lts-announce/2021/09/msg00012.html'
    label: security@apache.org
  - url: 'https://security.netapp.com/advisory/ntap-20211008-0005/'
    label: security@apache.org
  - url: 'https://www.debian.org/security/2021/dsa-4986'
    label: security@apache.org
  - url: >-
      https://lists.apache.org/thread.html/r6b6b674e3f168dd010e67dbe6848b866e2acf26371452fdae313b98a%40%3Cusers.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rb4de81ac647043541a32881099aa6eb5a23f1b7fd116f713f8ab9dbe%40%3Cdev.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://lists.apache.org/thread.html/rccdef0349fdf4fb73a4e4403095446d7fe6264e0a58e2df5c6799434%40%3Cannounce.tomcat.apache.org%3E
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://lists.debian.org/debian-lts-announce/2021/09/msg00012.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20211008-0005/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.debian.org/security/2021/dsa-4986'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.07182
epssPercentile: 0.94146
ingestedAt: '2026-10-08T23:16:47.322Z'
---

## Overview

Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.

## Affected

- `tomcat >= 8.5.0, < 8.5.64`
- `tomcat >= 9.0.0, < 9.0.44`
- `tomcat >= 10.0.0, <= 10.0.2`
- `debian_linux = 9.0`
- `debian_linux = 10.0`
- `debian_linux = 11.0`
- `management_services_for_element_software_and_netapp_hci`

## Remediation

Upgrade past the affected range:

- `tomcat 9.0.44`
