Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-38286

26
FAUCET Score

CVE-2024-38286 is a resource exhaustion vulnerability in Apache Tomcat, affecting versions 11.0.0-M1 through 11.0.0-M20, 10.1.0-M1 through 10.1.24, and 9.0.13 through 9.0.89, as well as several End-of-Life versions. An unauthenticated attacker can trigger an OutOfMemoryError by manipulating the TLS handshake process, leading to a denial of service. This vulnerability has a CVSS score of 7.5 (High) due to its network-based attack vector, low complexity, and high impact on availability. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or inclusion in the CISA KEV catalog, though it has received some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 9.0.13, < 9.0.90CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
>= 10.1.1, < 10.1.25CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
10.1.0CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:10.1.0:milestone1:*:*:*:*:*:*
10.1.0CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:10.1.0:milestone10:*:*:*:*:*:*
10.1.0CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:10.1.0:milestone11:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

8.6HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.70%
Probability of exploitation in next 30 days
EPSS Percentile
74.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0170 is in the 57th percentile among its peer group of 51,485 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (34)

mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-coyoteFixed in: 9.0.90
mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 11.0.0-M21
mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 10.1.25
mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 9.0.90
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-utilFixed in: 11.0.0-M21
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-utilFixed in: 10.1.25
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-utilFixed in: 9.0.90
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-coyoteFixed in: 11.0.0-M21
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-coyoteFixed in: 10.1.25
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: pki-core:10.6-8080020241014201334.693a3987
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: pki-deps:10.6-8080020241014222908.63b34585
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: tomcat-1:9.0.87-1.el9_4.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: pki-servlet-engine-1:9.0.43-4.el9_0.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: tomcat-1:9.0.87-1.el9_2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: pki-servlet-engine-1:9.0.50-1.el9_2.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5Fixed in: tomcat
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.8 on RHEL 7Fixed in: jws5-tomcat-0:9.0.87-5.redhat_00005.1.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.8 on RHEL 8Fixed in: jws5-tomcat-0:9.0.87-5.redhat_00005.1.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.8 on RHEL 9Fixed in: jws5-tomcat-0:9.0.87-5.redhat_00005.1.el9jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 6.0 on RHEL 8Fixed in: jws6-tomcat-0:10.1.8-10.redhat_00018.1.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 6.0 on RHEL 9Fixed in: jws6-tomcat-0:10.1.8-10.redhat_00018.1.el9jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: tomcat-1:9.0.87-1.el8_8.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: tomcat-1:9.0.87-1.el8_10.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: pki-deps:10.6-8020020241017135048.4cda2c84
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: pki-deps:10.6-8040020241017141927.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: pki-deps:10.6-8040020241017141927.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: pki-deps:10.6-8040020241017141927.522a0ee4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: pki-deps:10.6-8060020241017143140.ad008a3a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: pki-deps:10.6-8060020241017143140.ad008a3a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: pki-deps:10.6-8060020241017143140.ad008a3a
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: tomcat
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: pki-servlet-engine
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pki-deps:10.6/pki-servlet-engine

Vendor Advisories (2)

mavenGHSA-7jqf-v358-p8g7high

Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability

Nov 7, 2024
redhatCVE-2024-38286Important

tomcat: Denial of Service in Tomcat

Sep 23, 2024

References

lists.debian.org / debian-lts-announce/2025/01/msg00009.html
security.netapp.com / advisory/ntap-20241101-0010
Third Party Advisory
openwall.com / lists/oss-security/2024/09/23/2
Mailing List
lists.apache.org / thread/wms60cvbsz3fpbz9psxtfx8r41jl6d4s
Mailing List