CVE-2020-17527

HIGH

Apache Tomcat <10.0.0-M9, 9.0.39, 8.5.59 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2020-17527. PoCs published by forse01.

AI-analyzed exploit summary The repository appears to be a stub or incomplete PoC for CVE-2020-17527, containing only standard Tomcat configuration files and no exploit code. The README is empty, and no offensive techniques are present.

Description

While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the HTTP/2 connection, it is possible that information could leak between requests.

Exploits (1)

nomisec STUB 2 stars
by forse01 · poc
https://github.com/forse01/CVE-2020-17527-Tomcat

The repository appears to be a stub or incomplete PoC for CVE-2020-17527, containing only standard Tomcat configuration files and no exploit code. The README is empty, and no offensive techniques are present.

Classification
Stub 90%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Apache Tomcat
No auth needed
Prerequisites: None identified
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (24)

Core 24
Core References
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2020/12/03/3
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
https://lists.debian.org/debian-lts-announce/2020/12/msg00022.html
Third Party Advisory vendor-advisory x_refsource_gentoo
https://security.gentoo.org/glsa/202012-23
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2021/dsa-4835
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuApr2021.html
Third Party Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20201210-0003/
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com//security-alerts/cpujul2021.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpujan2022.html
Patch, Third Party Advisory x_refsource_misc
https://www.oracle.com/security-alerts/cpuapr2022.html

Scores

CVSS v3 7.5
EPSS 0.2462
EPSS Percentile 97.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (20)
apache/tomcat 9.0.0 milestone10 (23 CPE variants)
apache/tomcat 9.0.35-3.39.1
apache/tomcat 9.0.35-3.57.3
apache/tomcat 9.0.36
apache/tomcat 9.0.37
apache/tomcat 9.0.38
apache/tomcat 9.0.39
apache/tomcat 10.0.0 milestone1 (9 CPE variants)
apache/tomcat 8.5.1 - 8.5.59
debian/debian_linux 9.0
... and 10 more
Published Dec 03, 2020
Tracked Since Feb 18, 2026