In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated with that connection that were currently waiting for a WINDOW_UPDATE before allowing the application to write more data. These waiting streams each consumed a thread. A malicious client could therefore construct a series of HTTP/2 requests that would consume all available processing threads.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published: 2017-04-17T16:00:00

Updated: 2024-08-05T15:11:48.408Z

Reserved: 2017-01-29T00:00:00

Link: CVE-2017-5650

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2017-04-17T16:59:00.430

Modified: 2023-12-08T16:41:18.860

Link: CVE-2017-5650

cve-icon Redhat

Severity : Important

Publid Date: 2017-04-10T00:00:00Z

Links: CVE-2017-5650 - Bugzilla