CVE-2020-13935
HIGH NUCLEIApache Tomcat < 7.0.104 - Infinite Loop
Title source: ruleDescription
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple requests with invalid payload lengths could lead to a denial of service.
Exploits (2)
nomisec
WORKING POC
169 stars
by RedTeamPentesting · poc
https://github.com/RedTeamPentesting/CVE-2020-13935
Nuclei Templates (1)
Apache Tomcat WebSocket Frame Payload Length Validation Denial of Service
HIGHby sttlr
Shodan:
html:"Apache Tomcat"
References (17)
Scores
CVSS v3
7.5
EPSS
0.9174
EPSS Percentile
99.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-835
Status
published
Products (11)
apache/tomcat
9.0.0 milestone1 (27 CPE variants)
apache/tomcat
10.0.0 milestone1 (6 CPE variants)
apache/tomcat
7.0.27 - 7.0.104
canonical/ubuntu_linux
16.04
canonical/ubuntu_linux
20.04
debian/debian_linux
9.0
debian/debian_linux
10.0
mcafee/epolicy_orchestrator
5.9.0
mcafee/epolicy_orchestrator
5.9.1
mcafee/epolicy_orchestrator
5.10.0 (9 CPE variants)
... and 1 more
Published
Jul 14, 2020
Tracked Since
Feb 18, 2026