FlawAtlas
Search the atlas
CVE-2020-13935 High

CVE-2020-13935

The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 9.0.0 through 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.

Exploit probability 86.6%
Published March 6, 2024
Required by Not available
Last source change March 20, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

33 explicit affected versions

Maven org.apache.tomcat.embed:tomcat-embed-websocket

136 explicit affected versions

Maven org.apache.tomcat:tomcat

144 explicit affected versions

Maven org.apache.tomcat:tomcat-websocket

97 explicit affected versions

Bitnami tomcat

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2020-13935

The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.

View original source
Open Source Vulnerabilities BIT-tomcat-2020-13935

The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 9.0.0 through 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.

View original source
Open Source Vulnerabilities GHSA-m7jv-hq7h-mq7c

The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.

View original source

05 / REFERENCES

Further evidence