In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated with that connection that were currently waiting for a WINDOW_UPDATE before allowing the application to write more data. These waiting streams each consumed a thread. A malicious client could therefore construct a series of HTTP/2 requests that would consume all available processing threads.
Advisories
Source ID Title
Github GHSA Github GHSA GHSA-9785-w233-x6hv Improper Resource Shutdown or Release in Apache Tomcat
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2024-08-05T15:11:48.408Z

Reserved: 2017-01-29T00:00:00

Link: CVE-2017-5650

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-04-17T16:59:00.430

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-5650

cve-icon Redhat

Severity : Important

Publid Date: 2017-04-10T00:00:00Z

Links: CVE-2017-5650 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses