Disclosure summary
Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle certain inconsistent HTTP request headers, which allows remote attackers to trigger incorrect identification of a request's length and conduct request-smuggling attacks via (1) multiple Content-Length headers or (2) a Content-Length header and a "Transfer-Encoding: chunked" header. NOTE: this vulnerability exists because of an incomplete fix for CVE-2005-2090.
Source-reported weakness categories
CWE-20
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
NIST National Vulnerability Database · NVD-CVE-2013-4286
Open original source · Updated Oct 09, 2026
Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.
| Vendor | Product / association | Version / bounds |
|---|---|---|
| apache | tomcat | 7.0.0 |
| apache | tomcat | 7.0.0 |
| apache | tomcat | 7.0.1 |
| apache | tomcat | 7.0.2 |
| apache | tomcat | 7.0.2 |
| apache | tomcat | 7.0.3 |
| apache | tomcat | 7.0.4 |
| apache | tomcat | 7.0.4 |
| apache | tomcat | 7.0.10 |
| apache | tomcat | 7.0.11 |
| apache | tomcat | 7.0.12 |
| apache | tomcat | 7.0.13 |
| apache | tomcat | 7.0.14 |
| apache | tomcat | 7.0.15 |
| apache | tomcat | 7.0.16 |
| apache | tomcat | 7.0.17 |
| apache | tomcat | 7.0.18 |
| apache | tomcat | 7.0.19 |
| apache | tomcat | 7.0.20 |
| apache | tomcat | 7.0.21 |
| apache | tomcat | 7.0.22 |
| apache | tomcat | 7.0.23 |
| apache | tomcat | 7.0.24 |
| apache | tomcat | 7.0.25 |
| apache | tomcat | 7.0.26 |
| apache | tomcat | 7.0.27 |
| apache | tomcat | 7.0.28 |
| apache | tomcat | 7.0.29 |
| apache | tomcat | 7.0.30 |
| apache | tomcat | 7.0.31 |
| apache | tomcat | 7.0.32 |
| apache | tomcat | 7.0.33 |
| apache | tomcat | 7.0.34 |
| apache | tomcat | 7.0.35 |
| apache | tomcat | 7.0.36 |
| apache | tomcat | 7.0.37 |
| apache | tomcat | 7.0.38 |
| apache | tomcat | 7.0.39 |
| apache | tomcat | 7.0.40 |
| apache | tomcat | 7.0.41 |
| apache | tomcat | 7.0.42 |
| apache | tomcat | 7.0.43 |
| apache | tomcat | 7.0.44 |
| apache | tomcat | 7.0.45 |
| apache | tomcat | 7.0.46 |
| apache | tomcat | 8.0.0 |
| apache | tomcat | 8.0.0 |
| apache | tomcat | * {"versionEndIncluding":"6.0.37"} |
| apache | tomcat | 1.1.3 |
| apache | tomcat | 3.0 |
| apache | tomcat | 3.1 |
| apache | tomcat | 3.1.1 |
| apache | tomcat | 3.2 |
| apache | tomcat | 3.2.1 |
| apache | tomcat | 3.2.2 |
| apache | tomcat | 3.2.2 |
| apache | tomcat | 3.2.3 |
| apache | tomcat | 3.2.4 |
| apache | tomcat | 3.3 |
| apache | tomcat | 3.3.1 |
| apache | tomcat | 3.3.1a |
| apache | tomcat | 3.3.2 |
| apache | tomcat | 4 |
| apache | tomcat | 4.0.0 |
| apache | tomcat | 4.0.1 |
| apache | tomcat | 4.0.2 |
| apache | tomcat | 4.0.3 |
| apache | tomcat | 4.0.4 |
| apache | tomcat | 4.0.5 |
| apache | tomcat | 4.0.6 |
| apache | tomcat | 4.1.0 |
| apache | tomcat | 4.1.1 |
| apache | tomcat | 4.1.2 |
| apache | tomcat | 4.1.3 |
| apache | tomcat | 4.1.3 |
| apache | tomcat | 4.1.9 |
| apache | tomcat | 4.1.10 |
| apache | tomcat | 4.1.12 |
| apache | tomcat | 4.1.15 |
| apache | tomcat | 4.1.24 |
| apache | tomcat | 4.1.28 |
| apache | tomcat | 4.1.29 |
| apache | tomcat | 4.1.31 |
| apache | tomcat | 4.1.36 |
| apache | tomcat | 5 |
| apache | tomcat | 5.0.0 |
| apache | tomcat | 5.0.1 |
| apache | tomcat | 5.0.2 |
| apache | tomcat | 5.0.3 |
| apache | tomcat | 5.0.4 |
| apache | tomcat | 5.0.5 |
| apache | tomcat | 5.0.6 |
| apache | tomcat | 5.0.7 |
| apache | tomcat | 5.0.8 |
| apache | tomcat | 5.0.9 |
| apache | tomcat | 5.0.10 |
| apache | tomcat | 5.0.11 |
| apache | tomcat | 5.0.12 |
| apache | tomcat | 5.0.13 |
| apache | tomcat | 5.0.14 |
Showing 100 associations; open the original for the complete set.
Original records & references
- NIST NVD record
- CVE Program record
- bugzilla.redhat.com
- h20564.www2.hpe.com
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- rhn.redhat.com
- bugzilla.redhat.com
- h20564.www2.hpe.com
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- lists.apache.org
- rhn.redhat.com
PUBLISHED 2014-02-26T09:55:08-05:00
MODIFIED 2026-10-09T16:17:07-04:00
INGESTED 2026-10-10T20:50:17-04:00