CVE-2017-5651
Expected Behavior Violation in Apache Tomcat
Summary
Remediation
Upgrade to the fixed version using your package manager.
<!-- Update pom.xml dependency version to 8.5.13 for org.apache.tomcat.embed:tomcat-embed-core -->
<!-- Update pom.xml dependency version to 8.5.13 for org.apache.tomcat:tomcat-coyote -->
<!-- Update pom.xml dependency version to 9.0.0.M19 for org.apache.tomcat:tomcat-coyote -->
<!-- Update pom.xml dependency version to 9.0.0.M19 for org.apache.tomcat.embed:tomcat-embed-core -->
After upgrading, run your dependency scanner again to confirm the vulnerability is resolved.
Affected Packages (4)
| Package | Ecosystem | Affected | Fixed In |
|---|---|---|---|
| org.apache.tomcat.embed:tomcat-embed-core | maven | 8.5.0, 8.5.11, 8.5.12, 8.5.2 (+6 more) | 8.5.13 |
| org.apache.tomcat:tomcat-coyote | maven | 8.5.0, 8.5.11, 8.5.12, 8.5.2 (+6 more) | 8.5.13 |
| org.apache.tomcat:tomcat-coyote | maven | 9.0.0.M1, 9.0.0.M10, 9.0.0.M11, 9.0.0.M13 (+8 more) | 9.0.0.M19 |
| org.apache.tomcat.embed:tomcat-embed-core | maven | 9.0.0.M1, 9.0.0.M10, 9.0.0.M11, 9.0.0.M13 (+8 more) | 9.0.0.M19 |
Vulnerability Classification
Common Weakness Enumeration (CWE) identifiers for this vulnerability type.
- CWE-440
CVSS Score Breakdown
What the CVSS (Common Vulnerability Scoring System) 9.8 score means for each attack dimension.
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References
- https://nvd.nist.gov/vuln/detail/CVE-2017-5651ADVISORY
- https://github.com/apache/tomcat/commit/494429ca210641b6b7affe89a2b0a6c0ff70109bWEB
- https://github.com/apache/tomcat/commit/9233d9d6a018be4415d4d7d6cb4fe01176adf1a8WEB
- https://web.archive.org/web/20170420113605/http://www.securitytracker.com/id/1038219WEB
- https://web.archive.org/web/20170417124228/http://www.securityfocus.com/bid/97544WEB
- https://security.netapp.com/advisory/ntap-20180614-0001WEB
- https://security.gentoo.org/glsa/201705-09WEB
- https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0@%3Cdev.tomcat.apache.org%3EWEB
- https://lists.apache.org/thread.html/r48c1444845fe15a823e1374674bfc297d5008a5453788099ea14caf0%40%3Cdev.tomcat.apache.org%3EWEB
- https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d@%3Cdev.tomcat.apache.org%3EWEB
- https://lists.apache.org/thread.html/r3bbb800a816d0a51eccc5a228c58736960a9fffafa581a225834d97d%40%3Cdev.tomcat.apache.org%3EWEB
- https://lists.apache.org/thread.html/eb6efa8d59c45a7a9eff94c4b925467d3b3fec8ba7697f3daa314b04@%3Cdev.tomcat.apache.org%3EWEB
- https://lists.apache.org/thread.html/eb6efa8d59c45a7a9eff94c4b925467d3b3fec8ba7697f3daa314b04%40%3Cdev.tomcat.apache.org%3EWEB
- https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc@%3Cdev.tomcat.apache.org%3EWEB
- https://lists.apache.org/thread.html/b5e3f51d28cd5d9b1809f56594f2cf63dcd6a90429e16ea9f83bbedc%40%3Cdev.tomcat.apache.org%3EWEB
- https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a@%3Cdev.tomcat.apache.org%3EWEB
- https://lists.apache.org/thread.html/88855876c33f2f9c532ffb75bfee570ccf0b17ffa77493745af9a17a%40%3Cdev.tomcat.apache.org%3EWEB
- https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3@%3Cdev.tomcat.apache.org%3EWEB
- https://lists.apache.org/thread.html/6af47120905aa7d8fe12f42e8ff2284fb338ba141d3b77b8c7cb61b3%40%3Cdev.tomcat.apache.org%3EWEB
- https://lists.apache.org/thread.html/6694538826b87522fb723d2dcedd537e14ebe0a381d92e5525a531d8@%3Cannounce.tomcat.apache.org%3EWEB
- https://lists.apache.org/thread.html/6694538826b87522fb723d2dcedd537e14ebe0a381d92e5525a531d8%40%3Cannounce.tomcat.apache.org%3EWEB
- https://lists.apache.org/thread.html/5c0e00fd31efc11e147bf99d0f03c00a734447d3b131ab0818644cdb@%3Cdev.tomcat.apache.org%3EWEB
- https://lists.apache.org/thread.html/5c0e00fd31efc11e147bf99d0f03c00a734447d3b131ab0818644cdb%40%3Cdev.tomcat.apache.org%3EWEB
- https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551@%3Cdev.tomcat.apache.org%3EWEB
- https://lists.apache.org/thread.html/343558d982879bf88ec20dbf707f8c11255f8e219e81d45c4f8d0551%40%3Cdev.tomcat.apache.org%3EWEB
- https://github.com/search?q=repo%3Aapache%2Ftomcat+apache.coyote+path%3A%2F%5Eres%5C%2Fbnd%5C%2F%2F&type=codeWEB
- https://github.com/apache/tomcatPACKAGE
- https://bz.apache.org/bugzilla/show_bug.cgi?id=60918WEB
- https://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlWEB
Frequently Asked Questions
- What is CVE-2017-5651?
- Expected Behavior Violation in Apache Tomcat This vulnerability has been assigned a severity rating of CRITICAL (CVSS score: 9.8/10).
- How do I check if my project is affected by CVE-2017-5651?
- CVE-2017-5651 affects org.apache.tomcat.embed:tomcat-embed-core and org.apache.tomcat:tomcat-coyote. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2017-5651 and 200,000+ other known vulnerabilities.
Severity & Exploitability
Exploitation is straightforward and causes maximum impact. Patch immediately.
Also Known As
Related CVEs
- CVE-2026-43512CRITICAL
Apache Tomcat - Digest authenticator will authenticate any unknown user
- CVE-2025-53506HIGH
Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams
- CVE-2026-24880HIGH
Apache Tomcat has an HTTP Request/Response Smuggling vulnerability
- CVE-2026-29129HIGH
Apache Tomcat: Configured cipher preference order not preserved
- CVE-2024-38286HIGH
Apache Tomcat Allocation of Resources Without Limits or Throttling vulnerability
- CVE-2026-24734HIGH
Apache Tomcat has an Improper Input Validation vulnerability
- CVE-2025-31650MEDIUM
Apache Tomcat Denial of Service via invalid HTTP priority header
- CVE-2025-66614MEDIUM
Apache Tomcat - Client certificate verification bypass
Check if you're affected
Scan your dependencies to see if this vulnerability affects your projects.
Scan Your Dependencies