CVE-2024-24549 is an improper input-validation flaw in Apache Tomcat HTTP/2 request processing. When an HTTP/2 request exceeds configured header limits, Tomcat does not reset the associated HTTP/2 stream until it has processed all header data. An attacker can exploit this delayed stream reset with excessive headers or continued header fragments, forcing unnecessary processing and resource consumption. Affected releases are Tomcat 11.0.0-M1 through 11.0.0-M16, 10.1.0-M1 through 10.1.18, 9.0.0-M1 through 9.0.85, and 8.5.0 through 8.5.98; older end-of-life releases may also be affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository provides a proof-of-concept (PoC) exploit for CVE-2024-24549, a denial of service (DoS) vulnerability in Apache Tomcat version 9.0.83. The repository contains two main Python scripts: 'exploit-cve2024-24549.py' and 'exploit-test1.py'. Both scripts are designed to overwhelm a target Tomcat server by sending a massive number of HTTP requests with extremely large, randomly generated headers and payloads, using a configurable number of concurrent threads. The scripts allow customization of the target host, port, number of requests, concurrency, and logging. 'exploit-test1.py' targets specific endpoints, while 'exploit-cve2024-24549.py' targets the root endpoint. Both scripts log request results to 'requests.log'. The exploit is intended for educational and research purposes and demonstrates the potential for resource exhaustion and service disruption on vulnerable Tomcat servers.
This repository contains a Proof of Concept (PoC) exploit for CVE-2024-24549, a Denial of Service (DoS) vulnerability in Apache Tomcat (versions 8.5.0 through 8.5.98, 9.0.0-M1 through 9.0.85, 10.1.0-M1 through 10.1.18, and 11.0.0-M1 through 11.0.0-M16). The exploit is implemented in a single Python script (CVE-2024-24549.py) that floods a target server with concurrent HTTPS requests containing extremely large custom headers, exploiting improper input validation in Tomcat's HTTP/2 implementation. The script is configurable via command-line arguments for target host, port, number of requests, concurrency, and logging. The README.md provides detailed vulnerability information, affected versions, mitigation steps, and ethical usage guidelines. The exploit is a network-based DoS attack and does not provide shell access or code execution, but can exhaust server resources and disrupt service availability. No hardcoded IPs or domains are present; the default target is 'target-server' on port 443, which should be replaced with the actual vulnerable server address.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A denial-of-service vulnerability in Apache Tomcat's HTTP/2 processing where streams exceeding header limits are not reset promptly.
An Apache Tomcat denial-of-service vulnerability in HTTP/2 header handling.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.