FlawAtlas
Search the atlas
CVE-2021-25122 High

Apache Tomcat h2c request mix-up

When responding to new h2c connection requests, Apache Tomcat versions 9.0.0 through 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

Exploit probability 18.1%
Published March 6, 2024
Required by Not available
Last source change March 20, 2026

02 / AFFECTED SOFTWARE

Affected packages

Maven org.apache.tomcat.embed:tomcat-embed-core

112 explicit affected versions

Maven org.apache.tomcat:tomcat-coyote

10 explicit affected versions

Unknown Unknown

34 explicit affected versions

Bitnami tomcat

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2021-25122

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

View original source
Open Source Vulnerabilities BIT-tomcat-2021-25122

When responding to new h2c connection requests, Apache Tomcat versions 9.0.0 through 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

View original source
Open Source Vulnerabilities GHSA-j39c-c8hj-x4j3

When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.

View original source

05 / REFERENCES

Further evidence