<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 01:49:02 +0000</lastBuildDate>
    <item>
      <title>bdu:2020-04938</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2020-04938</link>
      <description>bdu:2020-04938</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2020-04938</guid>
    </item>
    <item>
      <title>BIT-tomcat-2020-13935</title>
      <link>https://cve.radiocsirt.org/vuln/bit-tomcat-2020-13935</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 9.0.0 through 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 9.0.0 through 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-tomcat-2020-13935</guid>
    </item>
    <item>
      <title>certfr-2020-avi-626 — De multiples vulnérabilités ont été découvertes dans Apache Tomcat.
Elles permettent à un attaquant de provoquer un dén…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2020-avi-626</link>
      <description>certfr-2020-avi-626</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2020-avi-626</guid>
    </item>
    <item>
      <title>cnvd-2020-46230</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2020-46230</link>
      <description>cnvd-2020-46230</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2020-46230</guid>
    </item>
    <item>
      <title>EUVD-2026-42094</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-42094</link>
      <description>EUVD-2026-42094</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-42094</guid>
    </item>
    <item>
      <title>fkie_cve-2020-13935</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2020-13935</link>
      <description>&lt;p&gt;The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2020-13935</guid>
    </item>
    <item>
      <title>GHSA-m7jv-hq7h-mq7c — Infinite Loop in Apache Tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m7jv-hq7h-mq7c</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat, Maven: org.apache.tomcat.embed:tomcat-embed-websocket, Maven: org.apache.tomcat:tomcat-websocket&lt;/p&gt;
&lt;p&gt;The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat, Maven: org.apache.tomcat.embed:tomcat-embed-websocket, Maven: org.apache.tomcat:tomcat-websocket&lt;/p&gt;
&lt;p&gt;The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m7jv-hq7h-mq7c</guid>
    </item>
    <item>
      <title>gsd-2020-13935</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2020-13935</link>
      <description>gsd-2020-13935</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2020-13935</guid>
    </item>
    <item>
      <title>openSUSE-SU-2020:1102-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2020:1102-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2020:1102-1</guid>
    </item>
    <item>
      <title>RHSA-2020:3303 — Red Hat Security Advisory: Red Hat JBoss Web Server 3.1 Service Pack 10 security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2020:3303</link>
      <description>&lt;p&gt;tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoS&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat: Mishandling of Transfer-Encoding header allows for HTTP request smuggling tomcat: multiple requests with invalid payload length in a WebSocket frame could lead to DoS&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2020:3303</guid>
    </item>
    <item>
      <title>SUSE-SU-2020:2037-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2020:2037-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2020:2037-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2020-13935</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13935</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9, Ubuntu:20.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9, Ubuntu:20.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2020-13935</guid>
    </item>
    <item>
      <title>WID-SEC-W-2022-0519 — Apache Tomcat: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0519</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache Tomcat ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache Tomcat ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2022-0519</guid>
    </item>
  </channel>
</rss>
