SB20250704167 - Multiple vulnerabilities in Apache Tomcat
Published: July 4, 2025 Updated: July 10, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 secuirty vulnerabilities.
1) Input validation error (CVE-ID: CVE-2025-52434)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when handling HTTP/2 requests with APR/Native. A remote attacker can send specially crafted HTTP requests to the server and perform a denial of service (DoS) attack.
2) Resource management error (CVE-ID: CVE-2025-52520)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to overflow in file upload limit. A remote attacker can send specially crafted requests to the server and perform a denial of service (DoS) attack.
3) Resource exhaustion (CVE-ID: CVE-2025-53506)
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling excessive HTTP/2 streams. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.107
- https://github.com/apache/tomcat/commit/8a83c3c42d20762782678932c14005cd3397a018
- https://lists.apache.org/thread/n7f5v6fzovfxkpqf5q0cztqqn0kjjs4p
- https://github.com/apache/tomcat/commit/927d66fbc294cb65242102b817a45fd80834e040
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.43
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.9
- https://lists.apache.org/thread/chm6r12x185lk0o4t50hkvx5zwzszr9p
- https://lists.apache.org/thread/mf7zqhz6j66ct0m9sr5902mmqohcrzhs
- https://github.com/apache/tomcat/commit/434772930f362145516dd60681134e7f0cf8115b
- https://lists.apache.org/thread/tfjqf1odwql63sb40lqpb7dvlffk15t7
- https://lists.apache.org/thread/cdfmz3l1blkbgpg9jdn9tg9rlv2bzwj5