https://seclists.org/oss-sec/2025/q2/100: CVE-2025-31650: Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
Published Apr 28, 2025
·Updated
Affected Software
3 affected components
Apache Tomcat>=9.0.76<=9.0.102
Apache Tomcat>=10.1.10<=10.1.39
Apache Tomcat>=11.0.0-M2<=11.0.5
Frequently Asked Questions
1
What is the severity of CVE-2025-31650?
The severity of CVE-2025-31650 is classified as important.
2
Which versions of Apache Tomcat are affected by CVE-2025-31650?
Apache Tomcat versions 9.0.76 through 9.0.102, 10.1.10 through 10.1.39, and 11.0.0-M2 through 11.0.5 are affected by CVE-2025-31650.
3
How does CVE-2025-31650 affect Apache Tomcat?
CVE-2025-31650 allows for a denial of service (DoS) via a malformed HTTP/2 PRIORITY_UPDATE frame.
4
How do I fix CVE-2025-31650?
To mitigate CVE-2025-31650, upgrade to a fixed version of Apache Tomcat beyond those listed as affected.
5
What is a denial of service (DoS) in the context of CVE-2025-31650?
In the context of CVE-2025-31650, a denial of service occurs when the server becomes unable to respond to legitimate requests due to exploitation of the vulnerability.