Medium severity5.3NVD Advisory· Published Jul 12, 2021· Updated Jun 17, 2026
CVE-2021-33037
CVE-2021-33037
Description
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only accept an HTTP/1.0 response; - Tomcat honoured the identify encoding; and - Tomcat did not ensure that, if present, the chunked encoding was the final encoding.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tomcat:tomcatMaven | >= 10.0.0-M1, < 10.0.7 | 10.0.7 |
org.apache.tomcat:tomcatMaven | >= 9.0.0-M1, < 9.0.48 | 9.0.48 |
org.apache.tomcat:tomcatMaven | >= 8.5.0, < 8.5.68 | 8.5.68 |
Affected products
73cpe:2.3:a:mcafee:epolicy_orchestrator:*:*:*:*:*:*:*:*+ 11 more
- cpe:2.3:a:mcafee:epolicy_orchestrator:*:*:*:*:*:*:*:*range: <5.10.0
- cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:-:*:*:*:*:*:*
- cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_10:*:*:*:*:*:*
- cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_1:*:*:*:*:*:*
- cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_2:*:*:*:*:*:*
- cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_3:*:*:*:*:*:*
- cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_4:*:*:*:*:*:*
- cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_5:*:*:*:*:*:*
- cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_6:*:*:*:*:*:*
- cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_7:*:*:*:*:*:*
- cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_8:*:*:*:*:*:*
- cpe:2.3:a:mcafee:epolicy_orchestrator:5.10.0:update_9:*:*:*:*:*:*
- cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_cloud_native_core_service_communication_proxy:1.14.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*Range: >=8.0.0.0,<=8.5.0.2
- cpe:2.3:a:oracle:communications_instant_messaging_server:10.0.1.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_policy_management:12.5.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_pricing_design_center:12.0.0.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_session_report_manager:*:*:*:*:*:*:*:*Range: >=8.0.0,<=8.2.4.0
- cpe:2.3:a:oracle:communications_session_route_manager:*:*:*:*:*:*:*:*Range: >=8.0.0,<=8.2.4
- cpe:2.3:a:oracle:graph_server_and_client:*:*:*:*:*:*:*:*Range: <21.4
- cpe:2.3:a:oracle:healthcare_translational_research:4.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:hospitality_cruise_shipboard_property_management_system:20.1.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:instantis_enterprisetrack:17.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:instantis_enterprisetrack:17.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:instantis_enterprisetrack:17.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:managed_file_transfer:12.2.1.3.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:managed_file_transfer:12.2.1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:managed_file_transfer:12.2.1.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:mysql_enterprise_monitor:*:*:*:*:*:*:*:*Range: <=8.0.25
cpe:2.3:a:oracle:sd-wan_edge:9.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:sd-wan_edge:9.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:sd-wan_edge:9.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:secure_global_desktop:5.6:*:*:*:*:*:*:*
cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.1.1:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.1.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.2.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:utilities_testing_accelerator:6.0.0.3.1:*:*:*:*:*:*:*
- osv-coords32 versionspkg:bitnami/tomcatpkg:maven/org.apache.tomcat/tomcatpkg:rpm/opensuse/tomcat&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/tomcat&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/tomcat&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/tomcat10&distro=openSUSE%20Tumbleweedpkg:rpm/suse/javapackages-tools&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/javapackages-tools&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/javapackages-tools&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/javapackages-tools&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/javapackages-tools&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/javapackages-tools&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209pkg:rpm/suse/tomcat&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP2pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP3pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/tomcat&distro=SUSE%20OpenStack%20Cloud%209pkg:rpm/suse/tomcat&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209
>= 8.5.0, < 8.5.67+ 31 more
- (no CPE)range: >= 8.5.0, < 8.5.67
- (no CPE)range: >= 10.0.0-M1, < 10.0.7
- (no CPE)range: < 9.0.36-lp152.2.25.1
- (no CPE)range: < 9.0.36-13.1
- (no CPE)range: < 9.0.43-2.1
- (no CPE)range: < 10.1.14-1.1
- (no CPE)range: < 2.0.1-13.1
- (no CPE)range: < 2.0.1-13.1
- (no CPE)range: < 2.0.1-13.1
- (no CPE)range: < 2.0.1-13.1
- (no CPE)range: < 2.0.1-13.1
- (no CPE)range: < 2.0.1-13.1
- (no CPE)range: < 9.0.36-4.63.1
- (no CPE)range: < 9.0.36-4.63.1
- (no CPE)range: < 9.0.36-4.63.1
- (no CPE)range: < 9.0.36-3.84.1
- (no CPE)range: < 9.0.36-3.84.1
- (no CPE)range: < 9.0.36-13.1
- (no CPE)range: < 9.0.36-13.1
- (no CPE)range: < 9.0.36-3.71.1
- (no CPE)range: < 9.0.36-3.71.1
- (no CPE)range: < 9.0.115-3.160.1
- (no CPE)range: < 9.0.36-4.63.1
- (no CPE)range: < 9.0.36-4.63.1
- (no CPE)range: < 9.0.36-3.84.1
- (no CPE)range: < 9.0.115-3.160.1
- (no CPE)range: < 9.0.36-3.71.1
- (no CPE)range: < 9.0.36-3.71.1
- (no CPE)range: < 9.0.36-3.84.1
- (no CPE)range: < 9.0.36-4.63.1
- (no CPE)range: < 9.0.36-3.71.1
- (no CPE)range: < 9.0.36-3.71.1
- Apache Software Foundation/Apache Tomcatv5Range: Apache Tomcat 10 10.0.0-M1 to 10.0.6
Patches
Vulnerability mechanics
References
38- www.oracle.com//security-alerts/cpujul2021.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujan2022.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpuoct2021.htmlnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-4vww-mc66-62m6ghsaADVISORY
- kc.mcafee.com/corporate/indexnvdThird Party AdvisoryWEB
- lists.apache.org/thread.html/r612a79269b0d5e5780c62dfd34286a8037232fec0bc6f1a7e60c9381%40%3Cannounce.tomcat.apache.org%3EnvdMailing ListVendor AdvisoryWEB
- lists.debian.org/debian-lts-announce/2021/08/msg00009.htmlnvdMailing ListThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-33037ghsaADVISORY
- security.gentoo.org/glsa/202208-34nvdThird Party AdvisoryWEB
- security.netapp.com/advisory/ntap-20210827-0007/nvdThird Party Advisory
- www.debian.org/security/2021/dsa-4952nvdThird Party AdvisoryWEB
- github.com/apache/tomcat/commit/05f9e8b00f5d9251fcd3c95dcfd6cf84177f46c8ghsaWEB
- github.com/apache/tomcat/commit/19d11556d0db99df291df33605f137976d152475ghsaWEB
- github.com/apache/tomcat/commit/3202703e6d635e39b74262e81f0cb4bcbe2170dcghsaWEB
- github.com/apache/tomcat/commit/45d70a86a901cbd534f8f570bed2aec9f7f7b88eghsaWEB
- github.com/apache/tomcat/commit/506134f957a4be2c5b4a9334f7b3435fc954dbc1ghsaWEB
- github.com/apache/tomcat/commit/8874fa02e9b36baa9ca6b226c0882c0190ca5a02ghsaWEB
- github.com/apache/tomcat/commit/a2c3dc4c96168743ac0bab613709a5bbdaec41d0ghsaWEB
- github.com/apache/tomcat/commit/da0e7cb093cf68b052d9175e469dbd0464441b0bghsaWEB
- github.com/apache/tomcat/commit/eee0d024c1b3171560c92eaba79dd6eb8eb11bcdghsaWEB
- lists.apache.org/thread.html/r290aee55b72811fd19e75ac80f6143716c079170c5671b96932ed44b@%3Ccommits.tomee.apache.org%3EghsaWEB
- lists.apache.org/thread.html/r40f921575aee8d7d34e53182f862c45cbb8f3d898c9d4e865c2ec262@%3Ccommits.tomee.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rc6ef52453bb996a98cb45442871a1db56b7c349939e45d829bf9ae37@%3Ccommits.tomee.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rd0dfea39829bc0606c936a16f6fca338127c86c0a1083970b45ac8d2@%3Ccommits.tomee.apache.org%3EghsaWEB
- lists.apache.org/thread.html/re01e7e93154e8bdf78a11a23f9686427bd3d51fc6e12c508645567b7@%3Ccommits.tomee.apache.org%3EghsaWEB
- lists.apache.org/thread.html/rf1b54fd3f52f998ca4829159a88cc4c23d6cef5c6447d00948e75c97@%3Ccommits.tomee.apache.org%3EghsaWEB
- lists.apache.org/thread/kovg1bft77xo34ksrcskh5nl50p69962ghsaWEB
- security.netapp.com/advisory/ntap-20210827-0007ghsaWEB
- tomcat.apache.org/security-10.htmlghsaWEB
- tomcat.apache.org/security-8.htmlghsaWEB
- tomcat.apache.org/security-9.htmlghsaWEB
- lists.apache.org/thread.html/r290aee55b72811fd19e75ac80f6143716c079170c5671b96932ed44b%40%3Ccommits.tomee.apache.org%3Envd
- lists.apache.org/thread.html/r40f921575aee8d7d34e53182f862c45cbb8f3d898c9d4e865c2ec262%40%3Ccommits.tomee.apache.org%3Envd
- lists.apache.org/thread.html/rc6ef52453bb996a98cb45442871a1db56b7c349939e45d829bf9ae37%40%3Ccommits.tomee.apache.org%3Envd
- lists.apache.org/thread.html/rd0dfea39829bc0606c936a16f6fca338127c86c0a1083970b45ac8d2%40%3Ccommits.tomee.apache.org%3Envd
- lists.apache.org/thread.html/re01e7e93154e8bdf78a11a23f9686427bd3d51fc6e12c508645567b7%40%3Ccommits.tomee.apache.org%3Envd
- lists.apache.org/thread.html/rf1b54fd3f52f998ca4829159a88cc4c23d6cef5c6447d00948e75c97%40%3Ccommits.tomee.apache.org%3Envd
News mentions
0No linked articles in our index yet.