Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-2733-1 | tomcat8 security update |
Debian DSA |
DSA-4952-1 | tomcat9 security update |
EUVD |
EUVD-2021-1563 | Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding. |
Github GHSA |
GHSA-4vww-mc66-62m6 | HTTP Request Smuggling in Apache Tomcat |
Ubuntu USN |
USN-5360-1 | Tomcat vulnerabilities |
Tue, 25 Aug 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Oracle agile Product Lifecycle Management
|
|
| CPEs | cpe:2.3:a:oracle:agile_product_lifecycle_management:9.3.6:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle agile Plm
|
Oracle agile Product Lifecycle Management
|
Subscriptions
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2024-08-03T23:42:19.203Z
Reserved: 2021-05-17T00:00:00.000Z
Link: CVE-2021-33037
No data.
Status : Modified
Published: 2021-07-12T15:15:08.400
Modified: 2026-08-25T16:28:27.310
Link: CVE-2021-33037
OpenCVE Enrichment
No data.
-
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
Debian DLA
Debian DSA
EUVD
Github GHSA
Ubuntu USN