Apache disclosed CVE-2021-25122, an HTTP/2 (h2c) request mix-up flaw in Tomcat that could cause a request to be associated with the wrong response. Under affected HTTP/2 configurations, the defect could expose one user to another user's application response, creating a risk of information disclosure and session or transaction confusion.
The issue affects Tomcat 8.5.0 through 8.5.63, 9.0.0.M1 through 9.0.43, and 10.0.0-M1 through 10.0.2. Organizations should upgrade to Tomcat 8.5.64, 9.0.44, or 10.0.4 or later, and assess applications using HTTP/2 for potential unintended response exposure; Tomcat 7 is not listed among the affected release lines.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Apache Tomcat added an additional fix for bug 64830, addressing an h2c edge case that could corrupt requests. The change restores leftover input to the socket wrapper before creating or selecting an HTTP upgrade processor, allowing buffered data to be processed correctly.
Apache Tomcat issued a security notice for CVE-2021-25122, described as an h2c request mix-up vulnerability.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
mail-archives.apache.org
Open sourcegithub.com
Open sourcetomcat.apache.org
Open sourcetomcat.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.