Description
Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."
Remediation
References
Related Vulnerabilities
MySQL CVE-2020-2895 Vulnerability (CVE-2020-2895)
WordPress CVE-2011-3125 Vulnerability (CVE-2011-3125)
Liferay Portal Observable Timing Discrepancy Vulnerability (CVE-2025-43754)
Internet Information Services Other Vulnerability (CVE-1999-1233)
Craft CMS Authorization Bypass Through User-Controlled Key Vulnerability (CVE-2026-29069)