CVE-2023-46589High· 7.5▾ TwilightApache Tomcat Improper Input Validation vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.5 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
Last analysed / modified upstream
2.7%
Improper Input Validation vulnerability in Apache Tomcat. Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82, and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.
org.apache.tomcat:tomcat-catalina >= 11.0.0-M1, < 11.0.0-M11org.apache.tomcat:tomcat-catalina >= 10.1.0-M1, < 10.1.16org.apache.tomcat:tomcat-catalina >= 9.0.0-M1, < 9.0.83org.apache.tomcat:tomcat-catalina >= 8.5.0, < 8.5.96org.apache.tomcat.embed:tomcat-embed-core >= 11.0.0-M1, < 11.0.0-M11org.apache.tomcat.embed:tomcat-embed-core >= 10.1.0-M1, < 10.1.16org.apache.tomcat.embed:tomcat-embed-core >= 9.0.0-M1, < 9.0.83org.apache.tomcat.embed:tomcat-embed-core >= 8.5.0, < 8.5.96org.apache.tomcat:tomcat-coyote >= 11.0.0-M1, < 11.0.0-M11Upgrade to a patched release:
org.apache.tomcat:tomcat-catalina 11.0.0-M11org.apache.tomcat:tomcat-catalina 10.1.16org.apache.tomcat:tomcat-catalina 9.0.83org.apache.tomcat:tomcat-catalina 8.5.96org.apache.tomcat.embed:tomcat-embed-core 11.0.0-M11org.apache.tomcat.embed:tomcat-embed-core 10.1.16org.apache.tomcat.embed:tomcat-embed-core 9.0.83org.apache.tomcat.embed:tomcat-embed-core 8.5.96org.apache.tomcat:tomcat-coyote 11.0.0-M11Connected by shared product, vendor, weakness, or advisory.
CVE-2021-45105Medium· 5.9Apache Log4j2 versions 2.0-alpha1 through 2.16.0 (excluding 2.12.3 and 2.3.1) did not protect from uncontrolled recursion from self-referential lookups
CVE-2026-58186High· 7.5The Apache Traffic Server webp_transform plugin can decode unsafely and serve mislabeled, cacheable responses. This issue affects Apache Traffic Server: from 8.0.0 through 8.1.11, from 9.0.0 through 9.2.14, from 10.0.0 through 10.1.3.…
CVE-2026-85532High· 7.5Apache WSS4J accepted attacker-controlled derived-key lengths and offsets without adequate bounds
CVE-2026-74761High· 7.5Improper input validation in TopicRegion in Apache ActiveMQ, Apache ActiveMQ Broker, and Apache ActiveMQ All on all platforms. An authenticated client can spoof clientId when removing a durable topic subscription. This issue affec…
CVE-2021-29425Medium· 4.8In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent di…
CVE-2026-84939Critical· 9.1Path traversal vulnerability in Apache FreeMarker template loading mechanism, if the attacker can specify an arbitrary malformed locale identifier to FreeMarker, and the localized lookup configuration setting is enabled (it's by default …