Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-0199

67
FAUCET Score

CVE-2019-0199 describes a denial-of-service vulnerability in Apache Tomcat versions 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37, specifically within its HTTP/2 implementation. Attackers could exploit this by sending excessive SETTINGS frames or keeping streams open without data transfer, leading to server-side thread exhaustion. This vulnerability carries a high CVSS score of 7.5, indicating a network-based attack with low complexity and a high impact on availability. While there is no evidence of active exploitation, public exploit code, or KEV listing, the vulnerability has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 8.5.0, <= 8.5.37CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
>= 9.0.1, <= 9.0.14CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
9.0.0CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:9.0.0:milestone1:*:*:*:*:*:*
9.0.0CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:9.0.0:milestone10:*:*:*:*:*:*
9.0.0CPE matchmatch criteria
cpe:2.3:a:apache:tomcat:9.0.0:milestone11:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.5HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.0

Exploit Intelligence

EPSS Score
72.86%
Probability of exploitation in next 30 days
EPSS Percentile
99.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.7286 is in the 99th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (29)

mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-coyoteFixed in: 9.0.16
mavenpatch availablevia ghsa
Product: org.apache.tomcat:tomcat-coyoteFixed in: 8.5.38
mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 8.5.38
mavenpatch availablevia ghsa
Product: org.apache.tomcat.embed:tomcat-embed-coreFixed in: 9.0.16
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 6Fixed in: jws5-jboss-logging-0:3.3.2-1.Final_redhat_00001.1.el6jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 6Fixed in: jws5-mod_cluster-0:1.4.1-1.Final_redhat_00001.2.el6jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 6Fixed in: jws5-tomcat-0:9.0.21-10.redhat_4.1.el6jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 6Fixed in: jws5-tomcat-native-0:1.2.21-34.redhat_34.el6jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 6Fixed in: jws5-tomcat-vault-0:1.1.8-1.Final_redhat_1.1.el6jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 7Fixed in: jws5-ecj-0:4.12.0-1.redhat_1.1.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 7Fixed in: jws5-javapackages-tools-0:3.4.1-5.15.11.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 7Fixed in: jws5-mod_cluster-0:1.4.1-1.Final_redhat_00001.2.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 7Fixed in: jws5-tomcat-0:9.0.21-10.redhat_4.1.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 7Fixed in: jws5-tomcat-native-0:1.2.21-34.redhat_34.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 7Fixed in: jws5-tomcat-vault-0:1.1.8-1.Final_redhat_1.1.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 8Fixed in: jws5-ecj-0:4.12.0-1.redhat_1.1.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 8Fixed in: jws5-javapackages-tools-0:3.4.1-5.15.11.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 8Fixed in: jws5-jboss-logging-0:3.3.2-1.Final_redhat_00001.1.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 8Fixed in: jws5-mod_cluster-0:1.4.1-1.Final_redhat_00001.2.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 8Fixed in: jws5-tomcat-0:9.0.21-10.redhat_4.1.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 8Fixed in: jws5-tomcat-native-0:1.2.21-34.redhat_34.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 8Fixed in: jws5-tomcat-vault-0:1.1.8-1.Final_redhat_1.1.el8jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Runtimes Spring Boot 2.1.12Fixed in: tomcat
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 7Fixed in: jws5-jboss-logging-0:3.3.2-1.Final_redhat_00001.1.el7jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 6Fixed in: jws5-ecj-0:4.12.0-1.redhat_1.1.el6jws
View patch
redhatpatch availablevia redhat_api
Product: Red Hat JBoss Web Server 5.2 on RHEL 6Fixed in: jws5-javapackages-tools-0:3.4.1-5.15.11.el6jws
View patch
redhatno patchvia redhat_api
Product: Red Hat support for Spring BootFixed in: tomcat
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: pki-deps:10.6/pki-servlet-container

Vendor Advisories (2)

mavenGHSA-qcxh-w3j9-58qrhigh

Apache Tomcat Denial of Service vulnerability

Jun 15, 2020
redhatCVE-2019-0199Important

tomcat: Apache Tomcat HTTP/2 DoS

Mar 25, 2019

References

lists.opensuse.org / opensuse-security-announce/2019-06/msg00090.html
lists.opensuse.org / opensuse-security-announce/2019-07/msg00013.html
lists.opensuse.org / opensuse-security-announce/2019-07/msg00054.html
access.redhat.com / errata/RHSA-2019:3929
access.redhat.com / errata/RHSA-2019:3931
lists.apache.org / thread.html/158ab719cf60448ddbb074798f09152fdb572fc8f781e70a56118d1a%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/1dd0a59c1295cc08ce4c9e7edae5ad2268acc9ba55adcefa0532e5ba%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/4c438fa4c78cb1ce8979077f668ab7145baf83e7c59f2faf7eccf094%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/7bb193bc68b28d21ff1c726fd38bea164deb6333b59eec2eb3661da6%40%3Cusers.tomcat.apache.org%3E
lists.apache.org / thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/9fe25f98bac6d66f8a663a15c37a98bc2d8f8bbed1d408791a3e4067%40%3Cusers.tomcat.apache.org%3E
lists.apache.org / thread.html/a7a201bd23e67fd3326c9b22b814dd0537d3270b3b54a768e2e7ef50%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/ac0185ce240a711b542a55bccf9349ab0c2f343d70cf7835e08fabc9%40%3Cannounce.apache.org%3E
lists.apache.org / thread.html/cf4eb2bd2083cebb3602a293c653f9a7faa96c86f672c876f25b37ef%40%3Cannounce.apache.org%3E
lists.apache.org / thread.html/dddb3590bac28fbe89f69f5ccbe26283d014ddc691abdd042de14600%40%3Cannounce.tomcat.apache.org%3E
lists.apache.org / thread.html/df1a2c1b87c8a6c500ecdbbaf134c7f1491c8d79d98b48c6b9f0fa6a%40%3Cannounce.tomcat.apache.org%3E
lists.apache.org / thread.html/e1b0b273b6e8ddcc72c9023bc2394b1276fc72664144bf21d0a87995%40%3Cannounce.tomcat.apache.org%3E
lists.apache.org / thread.html/e56886e1bac9319ecce81b3612dd7a1a43174a3a741a1c805e16880e%40%3Ccommits.tomee.apache.org%3E
lists.apache.org / thread.html/e85e83e9954f169bbb77b44baae5a33d8de878df557bb32b7f793661%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/e87733036e8c84ea648cdcdca3098f3c8a897e2652c33062b2b1535c%40%3Cusers.tomcat.apache.org%3E
lists.apache.org / thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/r6ccee4e849bc77df0840c7f853f6bd09d426f6741247da2b7429d5d9%40%3Cdev.tomcat.apache.org%3E
lists.apache.org / thread.html/raba0fabaf4d56d4325ab2aca8814f0b30a237ab83d8106b115ee279a%40%3Cdev.tomcat.apache.org%3E
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/NPHQEL5AQ6LZSZD2Y6TYZ4RC3WI7NXJ3
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/ZQTZ5BJ5F4KV6N53SGNKSW3UY5DBIQ46
seclists.org / bugtraq/2019/Dec/43
security.netapp.com / advisory/ntap-20190419-0001
Third Party Advisory
support.f5.com / csp/article/K17321505
debian.org / security/2019/dsa-4596
oracle.com / security-alerts/cpuapr2020.html
oracle.com / security-alerts/cpujan2020.html
oracle.com / technetwork/security-advisory/cpujul2019-5072835.html
securityfocus.com / bid/107674