Vulnerability record · CVE-2010-2227 · published 13 July 2010
CVE-2010-2227: Apache Tomcat invalid Transfer-Encoding header buffer recycling flaw
Apache · Tomcat
Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta mishandle an invalid Transfer-Encoding header, interfering with buffer recycling. This can cause an application outage or leak sensitive information from previously used buffers. The record gives no CVSS v3 score, only CVSS 2.0 base 6.4 (MEDIUM).
Description
Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."
AV:N/AC:L/Au:N/C:P/I:N/A:P
Automated analysis
high priorityRemote unauthenticated denial of service and information disclosure with a very high EPSS percentile, though no KEV listing or confirmed in-the-wild exploitation is recorded.
What it is
Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta mishandle an invalid Transfer-Encoding header, interfering with buffer recycling. This can cause an application outage or leak sensitive information from previously used buffers. The record gives no CVSS v3 score, only CVSS 2.0 base 6.4 (MEDIUM).
Impact
A remote unauthenticated attacker can cause a denial of service against the Tomcat application or read residual data from recycled buffers, potentially exposing sensitive information.
Attack surface
Reached over the network by sending a crafted HTTP request with an invalid Transfer-Encoding header; no authentication or user interaction is required per the AV:N/AC:L/Au:N vector.
Exploitation
Not listed in CISA KEV and no exploit tag appears in the references, but EPSS is high (0.54779, 98.97th percentile), indicating elevated likelihood of attempted exploitation.
What to do
- Upgrade Tomcat to a release after 5.5.29, 6.0.27, or the 7.0.0 beta line per the vendor security pages.
- Apply the Apache SVN patches referenced (revisions 958911, 958977, 959428) if upgrading is not immediately possible.
- Update bundled Tomcat in downstream products such as Geronimo, Fedora, openSUSE, and Apple distributions.
- Restrict or monitor inbound HTTP traffic for malformed Transfer-Encoding headers at the reverse proxy or WAF.
Detection
- Inspect web server and Tomcat access logs for requests with malformed or duplicate Transfer-Encoding headers.
- Monitor for sudden application outages or restarts on Tomcat hosts without a clear operational cause.
- Alert on anomalous response sizes or content patterns that could indicate buffer data leakage.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-2227 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-2227), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.