CVE-2016-6816 is an HTTP request-smuggling and response-injection vulnerability in Apache Tomcat caused by permissive parsing of invalid characters in HTTP request lines. It affects Tomcat 9.0.0.M1 through 9.0.0.M11, 8.5.0 through 8.5.6, 8.0.0.RC1 through 8.0.38, 7.0.0 through 7.0.72, and 6.0.0 through 6.0.47. When Tomcat is deployed behind an intermediary proxy that accepts the malformed characters but interprets them differently, an attacker can desynchronize request handling and inject data into an HTTP response.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
No valid public exploits. Mallory filtered out 1 candidate as fakes, detection scripts, or README-only repos.
All candidate exploits were filtered out by Mallory's validation.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
20 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
An HTTP request-smuggling vulnerability in Tomcat request-line parsing caused by accepting invalid characters, which can lead to HTTP response injection, cache poisoning, cross-site scripting, or information disclosure.
A Tomcat HTTP request-smuggling vulnerability in which invalid HTTP request-line characters can enable response injection, potentially permitting web-cache poisoning, XSS, or exposure of sensitive information.
A Tomcat HTTP request-smuggling vulnerability involving invalid characters in HTTP request lines; it can enable HTTP response injection, web-cache poisoning, XSS, or exposure of information from other users' requests when paired with a differently interpreting proxy.
HTTP request-smuggling vulnerability in Tomcat/JBoss Web caused by accepting invalid HTTP request-line characters, enabling response injection and cache poisoning when paired with a permissive proxy.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.