Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Maven

Apache Tomcat does not enforce the maxHttpHeaderSize limit

GHSA-43v2-6grp-9pp9 · CVE-2011-0534

Published · Modified

Description

Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.

Ready to move

Start Securing

Free, no credit card | First findings in minutes