FixVibe

high

Uncontrolled Resource Consumption in Apache Tomcat (CVE-2020-11996)

Apache Tomcat release lines 8.5.0 through 8.5.55, 9.0.0.M1 through 9.0.35, and 10.0.0-M1 through 10.0.0-M5 are affected by CVE-2020-11996, a high-severity HTTP/2 resource-consumption advisory that can impact availability when the vulnerable runtime and connector are deployed.

CVE-2020-11996GHSA-53hp-jpwq-2jgqCWE-400

Attacker Impact

CVE-2020-11996 is a high-severity availability issue in Apache Tomcat HTTP/2 handling. When an affected Tomcat runtime is deployed with a reachable HTTP/2 path, request sequences associated with the advisory can drive high CPU usage and make the service unresponsive.

A repository dependency match is not the same as confirmed production exposure. It identifies that the codebase can resolve to an affected Tomcat release line and should be triaged against the deployed runtime, connector configuration, and container or server image that actually serves traffic.

Affected Versions

Apache Tomcat vendor security pages list CVE-2020-11996 as affecting Tomcat 8.5.0 through 8.5.55, 9.0.0.M1 through 9.0.35, and 10.0.0-M1 through 10.0.0-M5. Fixed releases are 8.5.56, 9.0.36, and 10.0.0-M6 or later on the relevant line.

GitHub Advisory and NVD records also track the issue under GHSA-53hp-jpwq-2jgq, CWE-400, and a high CVSS availability impact.

Concrete Fixes

Upgrade the active Tomcat release line to 8.5.56, 9.0.36, 10.0.0-M6, or a newer maintained release. Keep direct Tomcat dependencies, embedded Tomcat packages, Spring Boot-managed versions, Tomcat BOMs, parent POMs, Gradle constraints, external Tomcat servers, and container base images aligned so an older runtime is not left behind.

After changing dependency metadata, rebuild the deployed WAR, JAR, image, or server package and verify the runtime version from the artifact or dependency tree. Review whether HTTP/2 is intentionally enabled and exposed, but use normal smoke tests rather than denial-of-service traffic as verification.

Covered by FixVibe

FixVibe's GitHub repo scans flag Maven and Gradle build files that resolve Apache Tomcat packages into the CVE-2020-11996 affected ranges, with the version, file and fixed release line.