org.apache.tomcat.embed:tomcat-embed-websocket
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.tomcat.embed:tomcat-embed-websocketpage 1 of 1
- CVE-2020-13935CRITICALCVSS 7.5EG 9.0fixed in 7.0.105, 8.5.57, 9.0.37 or 10.0.0-M7, by version range2020-07-14
vulnerable: 10.0.0-M1, 10.0.0-M3, 10.0.0-M4, 10.0.0-M5, 10.0.0-M6
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple reques…
- CVE-2024-23672MEDIUMCVSS 6.3EG 6.3fixed in 11.0.0-M17, 10.1.19, 9.0.86 or 8.5.99, by version range2024-03-13
vulnerable: 8.5.0 ... 8.5.98 (83 versions)
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 th…
Check whether org.apache.tomcat.embed:tomcat-embed-websocket is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.tomcat.embed:tomcat-embed-websocket CVEs against the assets you own.
Book a Demo →