Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.
Get an AI-powered plain-language explanation of this vulnerability and remediation steps.
Login to generate AI explanation36 reference(s) from NVD