CVE-2020-11996: Apache Tomcat

High severity, CVSS 7.5. EPSS: 26.7% chance of exploitation in the next 30 days.

A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.

Affected products

  • Apache Tomcat: from 8.5.0, up to and including 8.5.55; from 9.0.0, up to and including 9.0.35; version 9.0.0 only; version 10.0.0 only
  • Canonical Ubuntu Linux: version 20.04 only
  • Debian Debian Linux: version 9.0 only; version 10.0 only
  • Netapp Oncommand System Manager: version 3.0 only; version 3.1.3 only
  • Opensuse Leap: version 15.1 only; version 15.2 only
  • Oracle MySQL Enterprise Monitor: up to and including 8.0.21
  • Oracle Siebel UI Framework: up to and including 20.12
  • Oracle Workload Manager: version 12.2.0.1 only; version 18c only; version 19c only

Published 2020-06-26. Last modified 2026-10-08.