# CVE-2024-34750

## Summary

- **CVE ID:** CVE-2024-34750
- **Severity:** HIGH
- **CVSS Score:** 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
- **CWE:** CWE-755, CWE-400
- **Published:** Jul 3, 2024
- **Last Modified:** Sep 17, 2026

## Description

Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.0-M1 through 9.0.89.

The following versions were EOL at the time the CVE was created but are 
known to be affected: 8.5.0 though 8.5.100. Other EOL versions may also be affected.


Users are recommended to upgrade to version 11.0.0-M21, 10.1.25 or 9.0.90, which fixes the issue.

## Affected Products

- Apache Software Foundation — Apache Tomcat (11.0.0-M1)
- Apache Software Foundation — Apache Tomcat (10.1.0-M1)
- Apache Software Foundation — Apache Tomcat (9.0.0-M1)
- Apache Software Foundation — Apache Tomcat (8.5.0)
- Apache Software Foundation — Apache Tomcat (10.0.0-M1)

## References

- [CNA](https://lists.apache.org/thread/4kqf0bc9gxymjc2x7v3p7dvplnl77y8l)
- [CVE](https://security.netapp.com/advisory/ntap-20240816-0004/)
- [CVE](https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 4.60%
- **EPSS Percentile:** 91.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-17._