High severity7.5NVD Advisory· Published Oct 14, 2021· Updated Jun 17, 2026
CVE-2021-42340
CVE-2021-42340
Description
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial of service via an OutOfMemoryError.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tomcat:tomcatMaven | >= 10.1.0-M1, < 10.1.0-M6 | 10.1.0-M6 |
org.apache.tomcat:tomcatMaven | >= 10.0.0-M1, < 10.0.12 | 10.0.12 |
org.apache.tomcat:tomcatMaven | >= 9.0.40, < 9.0.54 | 9.0.54 |
org.apache.tomcat:tomcatMaven | >= 8.5.60, < 8.5.72 | 8.5.72 |
Affected products
38cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*+ 6 more
- cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*range: >=8.5.60,<8.5.72
- cpe:2.3:a:apache:tomcat:10.0.0:milestone10:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone1:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone2:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone3:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone4:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:10.1.0:milestone5:*:*:*:*:*:*
- cpe:2.3:a:netapp:management_services_for_element_software:-:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:big_data_spatial_and_graph:*:*:*:*:*:*:*:*Range: <23.1
- cpe:2.3:a:oracle:communications_diameter_signaling_router:*:*:*:*:*:*:*:*Range: >=8.0.0.0,<=8.5.0.2
- cpe:2.3:a:oracle:hospitality_cruise_shipboard_property_management_system:20.1.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:managed_file_transfer:12.2.1.3.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:managed_file_transfer:12.2.1.3.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:managed_file_transfer:12.2.1.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:middleware_common_libraries_and_tools:12.2.1.4.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:payment_interface:19.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:payment_interface:19.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:payment_interface:20.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_customer_insights:15.0.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:retail_customer_insights:15.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:retail_customer_insights:16.0.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_data_extractor_for_merchandising:15.0.2:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:retail_data_extractor_for_merchandising:15.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:retail_data_extractor_for_merchandising:16.0.2:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:retail_eftlink:21.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_financial_integration:16.0.1:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:retail_financial_integration:16.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:retail_financial_integration:19.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:retail_store_inventory_management:14.0.4.13:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:oracle:retail_store_inventory_management:14.0.4.13:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:retail_store_inventory_management:14.1.3.14:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:retail_store_inventory_management:14.1.3.5:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:retail_store_inventory_management:15.0.3.3:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:retail_store_inventory_management:15.0.3.8:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:retail_store_inventory_management:16.0.3.7:*:*:*:*:*:*:*
cpe:2.3:a:oracle:sd-wan_edge:9.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:sd-wan_edge:9.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:sd-wan_edge:9.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:taleo_platform:*:*:*:*:*:*:*:*
- osv-coords2 versions
>= 8.5.60, < 8.5.72+ 1 more
- (no CPE)range: >= 8.5.60, < 8.5.72
- (no CPE)range: >= 10.1.0-M1, < 10.1.0-M6
- Apache Software Foundation/Apache Tomcatv5Range: Apache Tomcat 10 10.0.0-M10 to 10.0.11
Patches
Vulnerability mechanics
References
20- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujan2022.htmlnvdPatchThird Party AdvisoryWEB
- www.oracle.com/security-alerts/cpujul2022.htmlnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-wph7-x527-w3h5ghsaADVISORY
- kc.mcafee.com/corporate/indexnvdThird Party AdvisoryWEB
- lists.apache.org/thread.html/r83a35be60f06aca2065f188ee542b9099695d57ced2e70e0885f905c%40%3Cannounce.tomcat.apache.org%3EnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2021-42340ghsaADVISORY
- security.gentoo.org/glsa/202208-34nvdThird Party AdvisoryWEB
- security.netapp.com/advisory/ntap-20211104-0001/nvdThird Party Advisory
- www.debian.org/security/2021/dsa-5009nvdThird Party AdvisoryWEB
- github.com/apache/tomcat/commit/31d62426645824bdfe076a0c0eafa904d90b4fb9ghsaWEB
- github.com/apache/tomcat/commit/80f1438ec45e77a07b96419808971838d259eb47ghsaWEB
- github.com/apache/tomcat/commit/d27535bdee95d252418201eb21e9d29476aa6b6aghsaWEB
- github.com/apache/tomcat/commit/d5a6660cba7f51589468937bf3bbad4db7810371ghsaWEB
- lists.apache.org/thread.html/r8097a2d1550aa78e585fc77e602b9046e6d4099d8d132497c5387784@%3Ccommits.myfaces.apache.org%3EghsaWEB
- security.netapp.com/advisory/ntap-20211104-0001ghsaWEB
- tomcat.apache.org/security-10.htmlghsaWEB
- tomcat.apache.org/security-8.htmlghsaWEB
- tomcat.apache.org/security-9.htmlghsaWEB
- lists.apache.org/thread.html/r8097a2d1550aa78e585fc77e602b9046e6d4099d8d132497c5387784%40%3Ccommits.myfaces.apache.org%3Envd
News mentions
0No linked articles in our index yet.