A flaw was found in Apache Tomcat, where an h2c direct connection did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests are made, an OutOfMemoryException could occur, leading to a denial of service. The highest threat from this vulnerability is to system availability.
mail-archives.apache.org/mod_mbox/tomcat-announce/202007.mbox/%3Cad62f54e-8fd7-e326-25f1-3bdf1ffa3818%40apache.org%3E
tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.0.0-M7
tomcat.apache.org/security-7.html#Fixed_in_Apache_Tomcat_7.0.105
tomcat.apache.org/security-8.html#Fixed_in_Apache_Tomcat_8.5.57
tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.37
bugzilla.redhat.com/show_bug.cgi?id=1857040
nvd.nist.gov/vuln/detail/CVE-2020-13934
www.cve.org/CVERecord?id=CVE-2020-13934