/Vulnerability Library

Apache Tomcat - HTTP Request Smuggling

CVE-2023-45648
Verified

Description

Apache Tomcat from versions 8.5.0 to 8.5.93, 9.0.0-M1 to 9.0.81, 10.1.0-M1 to 10.1.13, and 11.0.0-M1 to 11.0.0-M11 contain an improper input validation caused by incorrect parsing of HTTP trailer headers, letting attackers craft headers to cause request smuggling, exploit requires sending malicious trailer headers.

Severity

Medium

CVSS Score

5.3

Exploit Probability

6%

Affected Product

tomcat

Published Date

January 29, 2026

Template Author

0x_akoko

CVE-2023-45648.yaml
5.3Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVE ID:
cve-2023-45648
CWE ID:
cwe-444

References

https://lists.apache.org/thread/2pv8yz1pyp088tsxfb7ogltk9msk0jdphttps://hackerone.com/reports/2299692https://nvd.nist.gov/vuln/detail/CVE-2023-45648

Remediation Steps

Upgrade to version 11.0.0-M12, 10.1.14, 9.0.81, or 8.5.94 or later.