The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
AI analysis not yet available
Plain-English explanation, risk summary, and remediation steps will appear here once AI analysis is complete.
No Fix Known
No patch has been released yet. Apply workarounds or mitigations where available.
Published
CVE disclosed publicly
Last Modified
Most recent update
Indexed to CVEInsight
Added to this platform
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
37
Affected Products
18
References
apache / tomcat
| - |
| apache | tomcat | - | - |
| apache | tomcat | - | - |
| apache | tomcat | - | - |
| apache | tomcat | - | - |
| apache | tomcat | - | - |
| apache | tomcat | - | - |
| netapp | hci | - | - |
| netapp | management_services_for_element_software | - | - |
| debian | debian_linux | - | - |
| oracle | agile_engineering_data_management | - | - |
| oracle | big_data_spatial_and_graph | 23.1 | - |
| oracle | communications_diameter_signaling_router | 8.0.0.0 - 8.5.0.2 | - |
| oracle | hospitality_cruise_shipboard_property_management_system | - | - |
| oracle | managed_file_transfer | - | - |
| oracle | managed_file_transfer | - | - |
| oracle | middleware_common_libraries_and_tools | - | - |
| oracle | payment_interface | - | - |
| oracle | payment_interface | - | - |
| oracle | retail_customer_insights | - | - |
| oracle | retail_customer_insights | - | - |
| oracle | retail_data_extractor_for_merchandising | - | - |
| oracle | retail_data_extractor_for_merchandising | - | - |
| oracle | retail_eftlink | - | - |
| oracle | retail_financial_integration | - | - |
| oracle | retail_financial_integration | - | - |
| oracle | retail_store_inventory_management | - | - |
| oracle | retail_store_inventory_management | - | - |
| oracle | retail_store_inventory_management | - | - |
| oracle | retail_store_inventory_management | - | - |
| oracle | retail_store_inventory_management | - | - |
| oracle | retail_store_inventory_management | - | - |
| oracle | sd-wan_edge | - | - |
| oracle | sd-wan_edge | - | - |
| oracle | taleo_platform | - | - |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability
Impact