tomcat is vulnerable to Infinite Loop
75
High Risk
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
You are affected if you are using a version that falls within the vulnerable range.
tomcat is vulnerable to Infinite Loop in versions 7.0.27 - 7.0.104, 8.5.0 - 8.5.56 and 9.0.0 - 9.0.36.
Upgrade the org.apache.tomcat:tomcat library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant