Apache Tomcat - HTTP Request Smuggling
CVE-2023-45648
Verified
Description
Apache Tomcat from versions 8.5.0 to 8.5.93, 9.0.0-M1 to 9.0.81, 10.1.0-M1 to 10.1.13, and 11.0.0-M1 to 11.0.0-M11 contain an improper input validation caused by incorrect parsing of HTTP trailer headers, letting attackers craft headers to cause request smuggling, exploit requires sending malicious trailer headers.
Severity
Medium
CVSS Score
5.3
Exploit Probability
6%
Affected Product
tomcat
Published Date
January 29, 2026
Template Author
0x_akoko
CVE-2023-45648.yaml
5.3Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVE ID:
cve-2023-45648
CWE ID:
cwe-444
Remediation Steps
Upgrade to version 11.0.0-M12, 10.1.14, 9.0.81, or 8.5.94 or later.