CVE-2025-31650 is an improper input validation vulnerability in Apache Tomcat caused by incorrect error handling when processing certain invalid HTTP Priority headers. When such malformed headers are received, the failed request is not fully cleaned up, resulting in a memory leak. Repeated submission of these malformed requests can accumulate unreleased memory and eventually exhaust the Java heap. The issue affects Apache Tomcat 9.0.76 through 9.0.102, 10.1.10 through 10.1.39, and 11.0.0-M2 through 11.0.5. End-of-life Apache Tomcat 8.5.90 through 8.5.100 is also known to be affected.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (4 hidden).
This repository contains a Python proof-of-concept (PoC) exploit for CVE-2025-31650, a memory exhaustion (Denial of Service) vulnerability in Apache Tomcat's HTTP/2 implementation. The main file, PoC.py, is a standalone script that can both check for HTTP/2 support and Tomcat presence (using the --check-only flag) and launch a scalable DoS attack by sending a large number of HTTP/2 requests with malformed 'priority' headers. The script is asynchronous and allows the user to configure the number of concurrent tasks and requests per task. The README.md provides clear usage instructions, affected Tomcat versions, and a disclaimer. The exploit targets network-accessible Tomcat servers with HTTP/2 enabled and does not require authentication. The only fingerprintable endpoint is the user-supplied target URL. The code is a functional PoC and does not include weaponized or post-exploitation features.
This repository contains a Python-based proof-of-concept (PoC) exploit targeting Apache Tomcat versions 10.1.10 through 10.1.39. The exploit, implemented in 'main.py', performs a denial-of-service (DoS) attack by sending a high volume of asynchronous HTTP/2 requests with malformed 'priority' headers to a user-specified target. The tool uses the 'httpx' library for HTTP/2 support and is designed to be multi-threaded and asynchronous for maximum throughput. It includes real-time monitoring of the target's availability and provides a summary of successful and failed requests. The exploit is interactive, requiring the user to input the target URL, number of threads, and requests per thread. The README.md provides a concise overview of the tool's features and intended use. No hardcoded endpoints are present; the target is specified at runtime. The repository is structured simply, with a single main code file, a README, and a license. The exploit is suitable for research and testing of HTTP/2 handling in Tomcat servers, but could be used for disruptive purposes if misused.
This repository contains a proof-of-concept (PoC) exploit for CVE-2025-31650, a denial of service vulnerability in Apache Tomcat versions 10.1.10 through 10.1.39. The main file, '52318.py', is a Python script that uses the httpx library to send a large number of HTTP/2 requests with malformed 'priority' headers to a specified Tomcat server. The script is interactive, prompting the user for the target URL, number of concurrent tasks, and requests per task. It first validates the target and checks for HTTP/2 support, then launches the attack by flooding the server with requests designed to trigger a memory leak or crash. The script also monitors the server's availability during the attack. The README.md file contains a copy of the exploit code and a brief description. No backdoors, shell access, or destructive actions beyond denial of service are present. The exploit is network-based and targets any Tomcat server with HTTP/2 enabled within the vulnerable version range.
This repository contains a Python proof-of-concept exploit (PoC.py) and a README.md for CVE-2025-31650, a memory exhaustion (DoS) vulnerability in Apache Tomcat. The exploit targets Tomcat servers (versions 9.0.76–9.0.102, 10.1.10–10.1.39, 11.0.0-M2–11.0.5) with HTTP/2 enabled. The main script, PoC.py, allows the user to check if a target supports HTTP/2 and appears to be Tomcat, and then, if desired, launch a DoS attack by sending a high volume of HTTP/2 requests with malformed 'priority' headers. The script is asynchronous and configurable in terms of concurrency and request volume. The README provides usage instructions, affected versions, and a disclaimer. No hardcoded IPs or domains are present; the user supplies the target URL. The exploit is a functional PoC for research and authorized testing, not a weaponized tool.
This repository contains a Python-based exploit tool named 'TomcatKiller.py' targeting CVE-2025-31650, a vulnerability in Apache Tomcat versions 10.1.10 to 10.1.39. The exploit abuses improper handling of HTTP/2 priority headers, sending a high volume of requests with malformed or invalid 'priority' headers to the target server. This can trigger a memory leak, potentially leading to a denial-of-service (DoS) condition via OutOfMemoryError. The tool is interactive, prompting the user for the target URL, number of concurrent tasks, and requests per task. It verifies HTTP/2 support on the target before launching the attack and monitors server availability during execution. The repository is structured simply, with the main exploit logic contained in 'TomcatKiller.py', a README describing the vulnerability and usage, a license file, and a .gitignore. No hardcoded endpoints are present; the user supplies the target at runtime. The exploit is operational and suitable for authorized testing of Tomcat servers for this specific vulnerability.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
21 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A denial-of-service vulnerability in Apache Tomcat, potentially allowing attackers to disrupt service.
A vulnerability referenced as a trending CVE affecting Apache Tomcat (no technical details provided in the content).
A denial-of-service vulnerability in Apache Tomcat used by Atlassian products, potentially allowing attackers to disrupt services.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.