CVE-2020-11996

HIGH

Apache Tomcat <10.0.0-M6, <9.0.36, <8.5.56 - DoS

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-11996. PoCs published by rusakovichma.

AI-analyzed exploit summary This repository contains a proof-of-concept for CVE-2020-11996, an HTTP/2 request smuggling vulnerability in Apache Tomcat. The PoC is located in the testImplicitCloseLargeId unit test of TestHttp2Section_5_1.java, demonstrating the vulnerability in Tomcat embed core version 9.0.31.

Description

A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.

Exploits (1)

nomisec WORKING POC 5 stars
by rusakovichma · poc
https://github.com/rusakovichma/tomcat-embed-core-9.0.31-CVE-2020-11996

This repository contains a proof-of-concept for CVE-2020-11996, an HTTP/2 request smuggling vulnerability in Apache Tomcat. The PoC is located in the testImplicitCloseLargeId unit test of TestHttp2Section_5_1.java, demonstrating the vulnerability in Tomcat embed core version 9.0.31.

Classification
Working Poc 90%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Apache Tomcat 9.0.31
No auth needed
Prerequisites: Network access to the vulnerable Tomcat server · HTTP/2 support enabled on the server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (24)

Core 24
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/07/msg00010.html
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2020/dsa-4727
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00064.html
Mailing List, Third Party Advisory vendor-advisory x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2020-07/msg00072.html
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuoct2020.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20200709-0002/
Third Party Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4596-1/
Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2021.html

Scores

CVSS v3 7.5
EPSS 0.2670
EPSS Percentile 97.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

Status published
Products (20)
apache/tomcat 9.0.0 milestone1 (27 CPE variants)
apache/tomcat 10.0.0 milestone1 (5 CPE variants)
apache/tomcat 8.5.0 - 8.5.55
canonical/ubuntu_linux 20.04
debian/debian_linux 9.0
debian/debian_linux 10.0
netapp/oncommand_system_manager 3.0
netapp/oncommand_system_manager 3.1.3
opensuse/leap 15.1
opensuse/leap 15.2
... and 10 more
Published Jun 26, 2020
Tracked Since Feb 18, 2026