tomcat-embed-core is vulnerable to DOS
75
High Risk
Affected versions of this package are vulnerable to a Denial of Service (DoS) attack if the Tomcat server is configured to allow HTTP/2 requests.
You are affected if you use Tomcat (within the affected versions) to process HTTP/2 requests without a load balancer in front of it.
tomcat-embed-core is vulnerable to DOS in versions 10.0.0 - 10.1.18, 9.0.0 - 9.0.85 and 8.5.0 - 8.5.98.
Upgrade Tomcat to any of the patched versions.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant