PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Network Vulnerabilities·Updated Feb 22, 2026

Apache Tomcat - HTTP Request Smuggling

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
0
Continuously Checked
assets under CS
2
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-45648
5.3
CVSSmedium
Exploitable remotely over the internet · no authentication required.

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Apache Tomcatby Apache Software Foundation
11.0.0-M1
tomcatby apache
11.0.0-m1
Updated Sep 9, 2026View on NVD →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Apache Tomcat - HTTP Request Smuggling CVE-2023-45648 Scanner | S4E