Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat
High severity
GitHub Reviewed
Published
Feb 8, 2022
to the GitHub Advisory Database
•
Updated May 20, 2026
Description
Published by the National Vulnerability Database
Jul 14, 2020
Reviewed
Apr 12, 2021
Published to the GitHub Advisory Database
Feb 8, 2022
Last updated
May 20, 2026
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.
References