← Vulnerability feed

Vulnerability record · CVE-2011-5034 · published 30 December 2011

CVE-2011-5034: Apache Geronimo predictable hash collision denial of service

Apache · Geronimo

Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably. A remote attacker can send many crafted parameters that collide in the hash table, driving excessive CPU consumption. The record notes this may overlap CVE-2011-4461.

7.8 CVSS 2.0 High EPSS 81% · top 0.4% CWE-20 · Improper input validation
7.8CVSS 2.0 base score
81%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
34References
16 Jun 2026Last modified by NVD

Description

Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters. NOTE: this might overlap CVE-2011-4461.

AV:N/AC:L/Au:N/C:N/I:N/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityUnauthenticated remote denial of service with complete availability impact, a very high EPSS score, and a public proof-of-concept, though no KEV listing or active exploitation is confirmed.

What it is

Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger hash collisions predictably. A remote attacker can send many crafted parameters that collide in the hash table, driving excessive CPU consumption. The record notes this may overlap CVE-2011-4461.

Impact

An unauthenticated remote attacker can exhaust server CPU and cause a denial of service, degrading or halting the affected application. No data confidentiality or integrity impact is described; the CVSS vector rates availability as complete.

Attack surface

Reachable over the network via HTTP form parameter submission to the Geronimo application, per the AV:N vector. No authentication or user interaction is required (Au:N, and the description specifies remote attackers).

Exploitation

Not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high (0.80569, 99.6th percentile) and a public proof-of-concept hash collision script is referenced, indicating mature, widely available exploitation techniques.

What to do

  • Upgrade Apache Geronimo past 2.2.1 to a release that randomizes or restricts hash computation for form parameters.
  • If upgrade is not immediately possible, apply vendor or upstream patches addressing hash collision handling and limit the number of accepted form parameters per request.
  • Place the Geronimo application behind a reverse proxy or WAF that caps request parameter counts and request body size.
  • Rate-limit and monitor inbound requests to the affected endpoints to blunt high-volume collision floods.

Detection

  • Monitor CPU saturation on Geronimo hosts correlated with spikes in HTTP requests containing unusually large numbers of form parameters.
  • Alert on requests with abnormally high parameter counts or repeated parameter names from single sources.
  • Review web server and application logs for POST bodies with many crafted parameters targeting form-handling endpoints.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://archives.neohapsis.com/archives/bugtraq/2011-12/0181.html
http://secunia.com/advisories/47412
http://www.kb.cert.org/vuls/id/903934 US Government Resource
http://www.nruns.com/_downloads/advisory28122011.pdf
http://www.ocert.org/advisories/ocert-2011-003.html
https://github.com/FireFart/HashCollision-DOS-POC/blob/master/HashtablePOC.py
https://lists.apache.org/thread.html/r20957aa5962a48328f199e2373f408aeeae601a45dd5275a195e2b6e%40%3Cjava-dev.axis.apache
https://lists.apache.org/thread.html/r360b70489bad65286b49ceb5303a849d2a7ec7d1292774a7259579e1%40%3Cissues.karaf.apache.
https://lists.apache.org/thread.html/r3c541f019b74902e8e61d73e40ecc2837dfce1b744ad5546919b993c%40%3Cissues.karaf.apache.
https://lists.apache.org/thread.html/r4fe6b5ff1d48e23337304fd5ac983d89328aecbd1fa198cfc966fbd7%40%3Cdev.geronimo.apache.
https://lists.apache.org/thread.html/r653f633aa7b6ccbb8c338dbfcea7a00e4ae9d6f3e064a03cab8dc20d%40%3Cjava-dev.axis.apache
https://lists.apache.org/thread.html/r67747af92035942c9c413bd8394acbb8a1ace5833c0177014c825bc2%40%3Cissues.karaf.apache.
https://lists.apache.org/thread.html/r8dc1a0ae0e0cf9d2494b8cbd66562f99331c4cf635e7781850a9b9ba%40%3Cjava-dev.axis.apache
https://lists.apache.org/thread.html/ra10015f6f3c3c88b7d813383554e87c06347fe163487148669189b8e%40%3Cdev.geronimo.apache.
https://lists.apache.org/thread.html/ra1fe29f6399b68980f914d8613dee7f67d62a1a97722fe9cd56f4f5f%40%3Cdev.geronimo.apache.
https://lists.apache.org/thread.html/rb0e85243d7268f1d7a1edb5e6c7df885dbd300acabaaf4cb0e880518%40%3Cissues.karaf.apache.
https://lists.apache.org/thread.html/rdd67ea3e489134f653349fc2cb09828ac8462aa61dd776b505a3297a%40%3Cissues.karaf.apache.
http://archives.neohapsis.com/archives/bugtraq/2011-12/0181.html
http://secunia.com/advisories/47412
http://www.kb.cert.org/vuls/id/903934 US Government Resource
http://www.nruns.com/_downloads/advisory28122011.pdf
http://www.ocert.org/advisories/ocert-2011-003.html
https://github.com/FireFart/HashCollision-DOS-POC/blob/master/HashtablePOC.py
https://lists.apache.org/thread.html/r20957aa5962a48328f199e2373f408aeeae601a45dd5275a195e2b6e%40%3Cjava-dev.axis.apache
https://lists.apache.org/thread.html/r360b70489bad65286b49ceb5303a849d2a7ec7d1292774a7259579e1%40%3Cissues.karaf.apache.
https://lists.apache.org/thread.html/r3c541f019b74902e8e61d73e40ecc2837dfce1b744ad5546919b993c%40%3Cissues.karaf.apache.
https://lists.apache.org/thread.html/r4fe6b5ff1d48e23337304fd5ac983d89328aecbd1fa198cfc966fbd7%40%3Cdev.geronimo.apache.
https://lists.apache.org/thread.html/r653f633aa7b6ccbb8c338dbfcea7a00e4ae9d6f3e064a03cab8dc20d%40%3Cjava-dev.axis.apache
https://lists.apache.org/thread.html/r67747af92035942c9c413bd8394acbb8a1ace5833c0177014c825bc2%40%3Cissues.karaf.apache.
https://lists.apache.org/thread.html/r8dc1a0ae0e0cf9d2494b8cbd66562f99331c4cf635e7781850a9b9ba%40%3Cjava-dev.axis.apache
https://lists.apache.org/thread.html/ra10015f6f3c3c88b7d813383554e87c06347fe163487148669189b8e%40%3Cdev.geronimo.apache.
https://lists.apache.org/thread.html/ra1fe29f6399b68980f914d8613dee7f67d62a1a97722fe9cd56f4f5f%40%3Cdev.geronimo.apache.
https://lists.apache.org/thread.html/rb0e85243d7268f1d7a1edb5e6c7df885dbd300acabaaf4cb0e880518%40%3Cissues.karaf.apache.
https://lists.apache.org/thread.html/rdd67ea3e489134f653349fc2cb09828ac8462aa61dd776b505a3297a%40%3Cissues.karaf.apache.

Track CVE-2011-5034 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2013-1777Apache geronimo code injection vulnerabilityThe JMX Remoting functionality in Apache Geronimo 3.x before 3.0.1, as used in IBM WebSphere Application Server (WAS) Community Edition 3.0.0.3 and o…EPSS 9.8%10.0CVE-2007-4548Apache geronimo improper authentication vulnerabilityThe login method in LoginModule implementations in Apache Geronimo 2.0 does not throw FailedLoginException for failed logins, which allows remote att…EPSS 4.2%9.4CVE-2008-5518Apache geronimo path traversal vulnerabilityMultiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 on Windows all…EPSS 36%7.5CVE-2007-5797Apache geronimo improper authentication vulnerabilitySQLLoginModule in Apache Geronimo 2.0 through 2.1 does not throw an exception for a nonexistent username, which allows remote attackers to bypass aut…EPSS 3.1%6.8CVE-2009-0039Apache geronimo cross-site request forgery vulnerabilityMultiple cross-site request forgery (CSRF) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 …EPSS 11%5.0CVE-2007-5085Apache geronimo improper authentication vulnerabilityUnspecified vulnerability in the management EJB (MEJB) in Apache Geronimo before 2.0.2 allows remote attackers to bypass authentication and obtain "a…EPSS 3.2%4.3CVE-2009-0038Apache geronimo cross-site scripting vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1 through 2.1.3 allow r…EPSS 18%4.3CVE-2006-0254Apache geronimo vulnerabilityMultiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) …EPSS 32%

Source: NIST National Vulnerability Database (record CVE-2011-5034), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.