CVE-2021-41079

CVE-2021-41079: Apache Tomcat DoS with unexpected TLS packet

Vendor Apache Software Foundation
Product Apache Tomcat
Weakness CWE-20 · Input validation
Published September 16, 2021
Last update August 4, 2024

CVSS base score

What the vulnerability does

Description

Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.

Key dates

Disclosure timeline

September 16, 2021 CVE published
August 4, 2024 Record updated