tomcat-embed-core is vulnerable to DOS
75
High Risk
Affected versions of this package are vulnerable to a Denial of Service (DoS) attack if the Tomcat server is configured to allow HTTP/2 requests.
You are affected if you use Tomcat (within the affected versions) to process HTTP/2 requests without a load balancer in front of it.
tomcat-embed-core is vulnerable to DOS in versions 10.0.0 - 10.1.18, 9.0.0 - 9.0.85 and 8.5.0 - 8.5.98.
Upgrade Tomcat to any of the patched versions.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant