Attacker Impact
CVE-2020-11996 is a high-severity availability issue in Apache Tomcat HTTP/2 handling. When an affected Tomcat runtime is deployed with a reachable HTTP/2 path, request sequences associated with the advisory can drive high CPU usage and make the service unresponsive.
A repository dependency match is not the same as confirmed production exposure. It identifies that the codebase can resolve to an affected Tomcat release line and should be triaged against the deployed runtime, connector configuration, and container or server image that actually serves traffic.
Affected Versions
Apache Tomcat vendor security pages list CVE-2020-11996 as affecting Tomcat 8.5.0 through 8.5.55, 9.0.0.M1 through 9.0.35, and 10.0.0-M1 through 10.0.0-M5. Fixed releases are 8.5.56, 9.0.36, and 10.0.0-M6 or later on the relevant line.
GitHub Advisory and NVD records also track the issue under GHSA-53hp-jpwq-2jgq, CWE-400, and a high CVSS availability impact.
Concrete Fixes
Upgrade the active Tomcat release line to 8.5.56, 9.0.36, 10.0.0-M6, or a newer maintained release. Keep direct Tomcat dependencies, embedded Tomcat packages, Spring Boot-managed versions, Tomcat BOMs, parent POMs, Gradle constraints, external Tomcat servers, and container base images aligned so an older runtime is not left behind.
After changing dependency metadata, rebuild the deployed WAR, JAR, image, or server package and verify the runtime version from the artifact or dependency tree. Review whether HTTP/2 is intentionally enabled and exposed, but use normal smoke tests rather than denial-of-service traffic as verification.
Covered by FixVibe
FixVibe's GitHub repo scans flag Maven and Gradle build files that resolve Apache Tomcat packages into the CVE-2020-11996 affected ranges, with the version, file and fixed release line.
