CVE-2023-45648Disclosure(apache / debian_linux)

LOWCVSS 5.3 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M12 onwards, 10.1.14 onwards, 9.0.81 onwards or 8.5.94 onwards, which fix the issue.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • tomcat

Threat summary

  • Public PoC is present in monitored signal
  • 1 mentions across 1 observed day

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Products
debian_linuxtomcat

6 versions affected across 2 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-11: 1PoC Mentioned / Linked · 2026-02-11: 1Technical Details · 2026-02-11: 102-11
Signal classification1 categories
Disclosure
1100.0%
Referenced assets1 URL
By indicator
Full discourse1 post
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2023-45648 - medium 🚨 Apache Tomcat - HTTP Request Smuggling > Apache Tomcat from versions 8.5.0 to 8.5.93, 9.0.0-M1 to 9.0.81, 10.1.0-M1 to 10.1.13... 👾 https://cloud.projectdiscovery.io/library/CVE-2023-45648 @pdnuclei #NucleiTemplates #cve

    Post summary

    CVE‑2023‑45648 is an HTTP Request Smuggling flaw affecting various Apache Tomcat releases, with a link to a Project Discovery library for additional details.

    00010206
    890 followersView on X
CPE platform detail62 entries

62 of 62 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat---
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
OSdebiandebian_linux10.0--
OSdebiandebian_linux11.0--
OSdebiandebian_linux12.0--

Explore more