CVE-2020-13943: Apache Tomcat
Medium severity, CVSS 4.3. EPSS: 55% chance of exploitation in the next 30 days.
If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previous request rather than the intended headers. This could lead to users seeing responses for unexpected resources.
Affected products
- Apache Tomcat: version 8.5.0 only; version 8.5.1 only; version 8.5.2 only; version 8.5.3 only; version 8.5.4 only; version 8.5.5 only; …
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Oracle Instantis Enterprisetrack: version 17.1 only; version 17.2 only; version 17.3 only
- Oracle SD-WAN Edge: version 9.0 only
Published 2020-10-12. Last modified 2026-10-08.