FixVibe

// código / holofote

Apache Tomcat h2c Request Mix-Up Advisory

Affected Tomcat h2c handling can put request data on the wrong response path.

A pegada

Tomcat often reaches production through embedded servlet containers, Spring Boot-managed dependencies, platform BOMs, or container base images. CVE-2021-25122 is an h2c request mix-up advisory, so FixVibe treats a repo match as dependency evidence, not proof that the deployed service accepts HTTP/2 cleartext upgrade traffic or leaked request data.

Como funciona

The repo check looks for Tomcat embedded-core and Coyote Maven coordinates in Java build files. Exact declared versions produce the strongest signal; compatible manifest ranges are reported when they clearly allow affected 8.5.x, 9.0.x, or 10.0.x release lines. The finding stays scoped to dependency evidence and does not claim FixVibe sent h2c traffic.

O raio de impacto

If an affected Tomcat runtime is deployed with the vulnerable h2c path reachable, request headers and limited request body data can be mixed between users under the advisory conditions. A repo match should trigger dependency-tree review, artifact rebuild, connector review, and runtime verification before anyone treats it as confirmed production exposure.

// o que o fixvibe verifica

O que o FixVibe verifica

FixVibe repo scans look for high-confidence security patterns and dependency risk in source context. Reports identify the affected area and recommended fix. For check-specific questions about exact detection heuristics, active payload details, or source-code rule patterns, contact support@fixvibe.app.

Defesas blindadas

Upgrade the active Tomcat release line to 8.5.63, 9.0.43, 10.0.2, or newer. Update direct Tomcat artifacts, BOMs, Spring Boot-managed versions, Gradle constraints, or container base images as needed, then rebuild and redeploy the actual WAR, JAR, or image.

// rode no seu próprio app

Continue publicando enquanto o FixVibe vigia.

O FixVibe pressiona a superfície pública do seu app do jeito que um atacante faria — sem agente, sem instalação, sem cartão. Continuamos pesquisando novos padrões de vulnerabilidade e transformando isso em checks práticos e fixes prontos para Cursor, Claude e Copilot.

Código fonte
116
testes nessa categoria
módulos
76
checks dedicados de código fonte
todo scan
487+
testes em todas as categorias
  • Grátis — sem cartão, sem instalação, sem ping de Slack
  • Só colar uma URL — a gente crawla, sonda e reporta
  • Achados classificados por severidade, deduplicados no sinal
  • AI-ready prompts where code applies, plus operator steps for DNS/provider fixes
Rodar um scan grátis

// checks atuais · fixes práticos · publique com confiança

Apache Tomcat h2c Request Mix-Up Advisory — Holofote de Vulnerabilidade | FixVibe · FixVibe