Impact
Apache Tomcat incorrectly processes the Transfer‑Encoding header in HTTP/1.0 requests, which can lead to HTTP request smuggling. This flaw may let an attacker manipulate how Tomcat parses request boundaries, potentially causing a legitimate request from one user to be dropped or merged with another. The result is a loss of availability, as valid traffic can be disrupted.
Affected Systems
Apache Tomcat versions 11.0.0‑M1 through 11.0.25, 10.1.0‑M1 through 10.1.59, 9.0.47 through 9.0.121, and older EOL releases 8.5.67 through 8.5.100 are affected. Any unsupported or older builds may also be impacted.
Risk and Exploitability
The attack vector is network‑based; an attacker must send a crafted HTTP/1.0 request with a Transfer‑Encoding header to a Tomcat instance that is behind a reverse proxy. No EPSS score is provided and the vulnerability is not in CISA KEV, so public exploitation is not documented. Nevertheless, the bug can be used to disrupt services, and operators should treat it as a potential denial‑of‑service risk.
OpenCVE Enrichment