Impact
The vulnerability comes from incomplete cleanup of state after handling a malformed HTTP/2 request. This flaw can cause a subsequent request from another user to fail, potentially leading to a denial‑of‑service condition for legitimate traffic. It is an improper cleanup weakness (CWE‑459). No information indicates privilege escalation or code execution; the impact is limited to availability.
Affected Systems
Apache Software Foundation’s Apache Tomcat is affected, specifically versions 9.0.116 through 9.0.121, 10.1.53 through 10.1.59, and 11.0.19 through 11.0.25.
Risk and Exploitability
The CVSS score is not provided, and the EPSS score is unavailable, so the exploitation probability is unclear. The CVE is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote attacker sending a malformed HTTP/2 request to the Tomcat server; if successful, it could disrupt service for other users but would require the attacker to reach the application layer. The potential severity is a denial of service that could affect availability. While the EPSS is unknown, the lack of prior exploitation data suggests the risk is moderate, and a patch is recommended.
OpenCVE Enrichment