StackRadar

CVE-2025-31650

High

Advisory

Published 28 Apr 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.599
99th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
81
of 17,781 indexed, latest versions
Container images
86
deployed by those charts
Fix available
4 of 4
affected packages

Apache Tomcat Denial of Service via invalid HTTP priority header

Carried by container images the latest versions of 81 of 17,781 indexed charts deploy, on 86 images.

Affected packageAffected versionsFixed inImages
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+31 more9.0.104, 10.1.40, 11.0.672
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+11 more9.0.104, 10.1.40, 11.0.618
Apache Tomcatbitnami9.0.809.0.1041
tomcatbitnami9.0.80-19.0.1041
OSV records
BIT-tomcat-2025-31650GHSA-3p2h-wqq4-wf4h

Charts affected

81 by stars
ChartLatestAffected imagesRadar Score
k8sforjavak8sforjava0.1.01 of 1See more

k8sforjava k8sforjava 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
vincentgwzhang/k8sforjava:latesta9139f2cd98f
tomcat-embed-core@10.1.34
10.1.40

Open the chart page →

1,476
tdsfkubebb5.7.01 of 3See more

tdsf kubebb 5.7.0

1 of the 3 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
kubebb/mesh-api:v5.7.0a3879931dfa1
tomcat-embed-core@10.1.12
10.1.40

Open the chart page →

6,490
tomcatkubesphereVerified publisher0.4.0-r11 of 2See more

tomcat kubesphere 0.4.0-r1

1 of the 2 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
library/tomcat:8.5.41-alpine04feaf74f8bb
tomcat-coyote@8.5.41
no fix listed

Open the chart page →

1,383
fpga-operatorkubesphere-stable2.7.41 of 7See more

fpga-operator kubesphere-stable 2.7.4

1 of the 7 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
inaccel/coral:2.18c53744ed70b
tomcat-embed-core@9.0.83
9.0.104

Open the chart page →

5,759
stakitkvalitetsitVerified publisher0.3.111 of 3See more

stakit kvalitetsit 0.3.11

1 of the 3 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
tomcat-embed-core@10.1.24
10.1.40

Open the chart page →

7,802
komgalinkding0.2.31 of 1See more

komga linkding 0.2.3

1 of the 1 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
gotson/komga:1.22.0ba892ab3e082
tomcat-embed-core@10.1.33
10.1.40

Open the chart page →

3,131
tmdbluiscajl0.2.41 of 1See more

tmdb luiscajl 0.2.4

1 of the 1 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
lavandadelpatio/tmdb:latestded9377636e9
tomcat-embed-core@10.1.15
10.1.40

Open the chart page →

2,234
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
tomcat-embed-core@10.1.13
10.1.40

Open the chart page →

3,683
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
tomcat-embed-core@10.1.13
10.1.40

Open the chart page →

5,129
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
tomcat-embed-core@10.1.13
10.1.40

Open the chart page →

4,599
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
tomcat-embed-core@8.5.31
no fix listed

Open the chart page →

15,855
crowdmoxVerified publisher2.4.31 of 3See more

crowd mox 2.4.3

1 of the 3 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
atlassian/crowd:5.2.2ebf761c7d437
tomcat-coyote@9.0.82
9.0.104

Open the chart page →

5,663
myappmyapp-helm-charts0.4.01 of 1See more

myapp myapp-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
adityaprasadpathak/myapp:3.07e3b9777362c
tomcat-embed-core@10.1.25
10.1.40

Open the chart page →

2,141
nacosnacos-yunyeVerified publisher1.0.31 of 1See more

nacos nacos-yunye 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.130a39cb0c54d
tomcat-embed-core@10.1.39
10.1.40

Open the chart page →

1,783
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
tomcat-coyote@8.5.38
tomcat-embed-core@8.5.38
no fix listed
no fix listed

Open the chart page →

63,223
ves-agentopencord1.0.21 of 1See more

ves-agent opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
opencord/ves-agent:1.0.04187e2a8c918
tomcat-embed-core@8.5.31
no fix listed

Open the chart page →

6,350
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
tomcat-embed-core@10.1.39
10.1.40

Open the chart page →

7,792
redhat-springboot-restopenshift0.0.11 of 1See more

redhat-springboot-rest openshift 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
tomcat-embed-core@9.0.83
9.0.104

Open the chart page →

3,063
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
tomcat-embed-core@10.1.39
10.1.40

Open the chart page →

2,003
iparedhat-cop1.3.91 of 1See more

ipa redhat-cop 1.3.9

1 of the 1 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
quay.io/freeipa/freeipa-server:fedora-39-4.11.1d422ee50c2c3
tomcat-coyote@9.0.83
9.0.104

Open the chart page →

951
seataseataVerified publisher0.1.01 of 1See more

seata seata 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
seataio/seata-server:latest703b5de7f1a6
tomcat-embed-core@9.0.83
9.0.104

Open the chart page →

4,245
seldon-core-oauth-gatewayseldon0.3.11 of 2See more

seldon-core-oauth-gateway seldon 0.3.1

1 of the 2 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
seldonio/apife:0.3.1eea0d3f578ca
tomcat-embed-core@8.5.34
no fix listed

Open the chart page →

8,098
guacamolesergiotocaliniVerified publisher1.0.01 of 2See more

guacamole sergiotocalini 1.0.0

1 of the 2 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
guacamole/guacamole:1.5.50f62f6d17ab3
tomcat-coyote@8.5.98
no fix listed

Open the chart page →

5,456
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
tomcat-coyote@8.5.57
no fix listed

Open the chart page →

13,079
sonarqubestakaterVerified publisher0.10.31 of 2See more

sonarqube stakater 0.10.3

1 of the 2 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
library/sonarqube:6.7.6-community0ae5169e3d0f
tomcat-embed-core@8.5.23
no fix listed

Open the chart page →

11,841
streamastreama1.0.11 of 2See more

streama streama 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
just1not2/streama:1.10.48a2305192dec
tomcat-embed-core@8.5.11
no fix listed

Open the chart page →

8,554
togglr-backendtogglrVerified publisher1.0.01 of 1See more

togglr-backend togglr 1.0.0

1 of the 1 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
tomcat-embed-core@10.1.15
10.1.40

Open the chart page →

3,221
configservertwomartensVerified publisher0.2.01 of 1See more

configserver twomartens 0.2.0

1 of the 1 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
2martens/configserver:latestbf1cdb80239d
tomcat-embed-core@10.1.28
10.1.40

Open the chart page →

2,144
drillwearefrank1.3.61 of 3See more

drill wearefrank 1.3.6

1 of the 3 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
apache/drill:1.21.11f96558fd292
tomcat-embed-core@8.5.46
no fix listed

Open the chart page →

9,397
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
tomcat-embed-core@8.5.41
no fix listed

Open the chart page →

5,460
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-31650.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
tomcat-embed-core@10.1.10
10.1.40

Open the chart page →

3,480

Container images carrying it

86 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
supertokens/supertokens-postgresql:3.1418d34c781347
tomcat-embed-core@8.5.47
no fix listed
3
apache/fineract:1.12.1a83cf1980609
tomcat-embed-core@10.1.39
10.1.40
2
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
tomcat-embed-core@8.5.31
no fix listed
2
inaccel/coral:2.18c53744ed70b
tomcat-embed-core@9.0.83
9.0.104
2
2martens/configserver:latestbf1cdb80239d
tomcat-embed-core@10.1.28
10.1.40
1
adityaprasadpathak/myapp:3.07e3b9777362c
tomcat-embed-core@10.1.25
10.1.40
1
anguda/ant-media:2.5c435285fc241
tomcat-coyote@8.5.82
tomcat-embed-core@8.5.82
no fix listed
no fix listed
1
apache/drill:1.21.11f96558fd292
tomcat-embed-core@8.5.46
no fix listed
1
apache/hertzbeat:1.8.075d48a62748f
tomcat-embed-core@10.1.34
10.1.40
1
apache/hertzbeat-collector:1.8.0a2bab1be574c
tomcat-embed-core@10.1.34
10.1.40
1
apache/iotdb:0.11.28647309f95d1
tomcat-embed-core@8.5.32
no fix listed
1
apache/ranger:2.7.076c176e8a0e4
tomcat-embed-core@9.0.98
9.0.104
1
apache/rocketmq:5.3.0434d8398f996
tomcat-embed-core@8.5.46
no fix listed
1
apache/rocketmq:4.9.35ac2a4e0f627
tomcat-embed-core@8.5.46
no fix listed
1
apache/skywalking-ui:8.1.067d50e4deff4
tomcat-embed-core@8.5.29
no fix listed
1
atlassian/crowd:5.2.2ebf761c7d437
tomcat-coyote@9.0.82
9.0.104
1
atlassian/jira-software:8.14.037bc46cbec1a
tomcat-coyote@8.5.57
no fix listed
1
castlemock/castlemock:latestb7f3f1527ba9
tomcat-coyote@11.0.5
tomcat-embed-core@11.0.5
11.0.6
11.0.6
1
choerodon/event-store-service:0.8.03c94c97f6f69
tomcat-embed-core@8.5.14
no fix listed
1
eclipseaerios/entrypoint-balancer:1.3.043cd999a008d
tomcat-embed-core@10.1.19
10.1.40
1
eclipseaerios/management-portal-backend:1.2.215fba526a4f8
tomcat-embed-core@10.1.19
10.1.40
1
fabioformosa/hello-world-api:latest063873af085c
tomcat-embed-core@10.1.39
10.1.40
1
flofree/base-project:2.1.16b6486c5f81e
tomcat-embed-core@9.0.78
9.0.104
1
flowable/flowable-rest:7.1.0b7ae287502cd
tomcat-embed-core@10.1.30
10.1.40
1
folioci/mod-ldp:latestb55696fd9065
tomcat-embed-core@10.1.19
10.1.40
1
freeipa/freeipa-server:fedora-37-4.10.1c87d77342bf5
tomcat-coyote@9.0.82
9.0.104
1
gdrocha/togglr-backend:1.0.0d5ae64e83d4c
tomcat-embed-core@10.1.15
10.1.40
1
golenski/fibonacci-msg-relay:1.0.0c863dcb0c513
tomcat-embed-core@10.1.31
10.1.40
1
golenski/fibonacci-task-manager:2.0.03a2b36df247b
tomcat-embed-core@10.1.31
10.1.40
1
golenski/fibonacci-worker:2.0.0954caf4aaf6a
tomcat-embed-core@10.1.31
10.1.40
1
gotson/komga:1.22.0ba892ab3e082
tomcat-embed-core@10.1.33
10.1.40
1
guacamole/guacamole:1.5.50f62f6d17ab3
tomcat-coyote@8.5.98
no fix listed
1
guacamole/guacamole:1.1.0333a7f40c145
tomcat-coyote@8.5.41
no fix listed
1
guacamole/guacamole:1.3.0739cb6820ae8
tomcat-coyote@8.5.61
no fix listed
1
hmediade/printserver:latest481a552c8e1c
tomcat-coyote@9.0.85
9.0.104
1
huajuan6848/env-view-server:0.0.1-SNAPSHOTa303f3d9f6e0
tomcat-embed-core@10.1.11
10.1.40
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
tomcat-embed-core@8.5.15
no fix listed
1
ibmcom/microclimate-theia:lateste17bdccc5030
tomcat-embed-core@8.5.15
no fix listed
1
intelloop/atlas-cmms-backend:v1.5.14c61bc3dd3f8
tomcat-embed-core@10.1.19
10.1.40
1
jacobalberty/unifi:5.10.19c409924e2463
tomcat-embed-core@8.5.34
no fix listed
1
javaaurelio/dadosfake_web_springboot:latest8541a3cd021a
tomcat-embed-core@10.1.15
10.1.40
1
just1not2/streama:1.10.48a2305192dec
tomcat-embed-core@8.5.11
no fix listed
1
kimb88/hello-world-spring-boot:latest0639155241cb
tomcat-embed-core@8.5.32
no fix listed
1
kubebb/mesh-api:v5.7.0a3879931dfa1
tomcat-embed-core@10.1.12
10.1.40
1
kvalitetsit/stakit-backend:0.3.0f0af0ba589af
tomcat-embed-core@10.1.24
10.1.40
1
lavandadelpatio/tmdb:latestded9377636e9
tomcat-embed-core@10.1.15
10.1.40
1
library/sonarqube:6.7.6-community0ae5169e3d0f
tomcat-embed-core@8.5.23
no fix listed
1
library/sonarqube:8.2-communitya246bc64207e
tomcat-embed-core@8.5.41
no fix listed
1
library/tomcat:8.5.41-alpine04feaf74f8bb
tomcat-coyote@8.5.41
no fix listed
1
linuxserver/airsonic-advanced:11.1.4d286a7f55a59
tomcat-embed-core@10.1.28
10.1.40
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.