HIGH 7.5 Maven

Infinite loop in Tomcat due to parsing error

GHSA-59g9-7gfx-c72p · BIT-tomcat-2021-41079 · CVE-2021-41079

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.

Ready to move

Start Securing

Free, no credit card | First findings in minutes