CVE-2025-48988
published 2025-06-16CVE-2025-48988: Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from…
PriorityP262high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
53.28%
98.9th percentile
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions
may also be affected.
Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | >= 10.1.0 < 10.1.42 | 10.1.42 |
| apache | tomcat | >= 11.0.0 < 11.0.8 | 11.0.8 |
| apache | tomcat | >= 9.0.0 < 9.0.106 | 9.0.106 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.41 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.7 | — |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.0.M1 – 9.0.105 | — |
| debian | tomcat10 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
| debian | tomcat11 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →The attack vector is a specially crafted HTTP multipart request containing an excessively large number of multipart sections, triggering excessive memory consumption and DoS on Apache Tomcat. ↗
- →Monitor Apache Tomcat servers for HTTP multipart upload requests with an abnormally high number of multipart sections, which may indicate exploitation attempts. ↗
- ·Affected Apache Tomcat versions span multiple branches: 9.0.0.M1–9.0.105, 10.1.0-M1–10.1.41, 11.0.0-M1–11.0.7, and EOL branch 8.5.0–8.5.100. Fixed versions are 9.0.106, 10.1.42, and 11.0.8. ↗
- ·No mitigation short of upgrading is available per Red Hat Product Security criteria; many downstream packages have fixes deferred. ↗
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Siebel CRM Risk Matrix: User Interface (Apache Tomcat) — CVE-2025-48988
vendor_oracle·2025-10-15·CVSS 7.5
CVE-2025-48988 [HIGH] Oracle Oracle Siebel CRM Risk Matrix: User Interface (Apache Tomcat) — CVE-2025-48988
Oracle Oracle Siebel CRM Risk Matrix: User Interface (Apache Tomcat) vulnerability
CVE: CVE-2025-48988
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Core (Apache Tomcat) — CVE-2025-48988
vendor_oracle·2025-07-15·CVSS 4.9
CVE-2025-48988 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Core (Apache Tomcat) — CVE-2025-48988
Oracle Oracle Communications Applications Risk Matrix: Core (Apache Tomcat) vulnerability
CVE: CVE-2025-48988
CVSS: 4.9
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujul2025 (JUL 2025)
Red Hat
tomcat: Apache Tomcat DoS in multipart upload
vendor_redhat·2025-06-16·CVSS 7.5
CVE-2025-48988 [HIGH] CWE-770 tomcat: Apache Tomcat DoS in multipart upload
tomcat: Apache Tomcat DoS in multipart upload
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions
may also be affected.
Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
A denial-of-service (DoS) vulnerability has been identified in Apache Tomcat, concerning its handling of upload limits. A remote attacker could exploit this flaw by sending a specially crafted request containing an excessively large number of multipart sections. This malicious req
Debian
CVE-2025-48988: tomcat10 - Allocation of Resources Without Limits or Throttling vulnerability in Apache Tom...
vendor_debian·2025·CVSS 7.5
CVE-2025-48988 [HIGH] CVE-2025-48988: tomcat10 - Allocation of Resources Without Limits or Throttling vulnerability in Apache Tom...
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
Scope: local
bookworm: resolved (fixed in 10.1.52-1~deb12u1)
forky: resolved (fixed in 10.1.46-1)
sid: resolved (fixed in 10.1.46-1)
trixie: resolved (fixed in 10.1.52-1~deb13u1)
GHSA
Apache Tomcat - DoS in multipart upload
ghsa·2025-06-16
CVE-2025-48988 [HIGH] CWE-770 Apache Tomcat - DoS in multipart upload
Apache Tomcat - DoS in multipart upload
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
OSV
CVE-2025-48988: Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat
osv·2025-06-16·CVSS 7.5
CVE-2025-48988 [HIGH] CVE-2025-48988: Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
OSV
Apache Tomcat - DoS in multipart upload
osv·2025-06-16
CVE-2025-48988 [HIGH] Apache Tomcat - DoS in multipart upload
Apache Tomcat - DoS in multipart upload
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2025-48988 tomcat: Apache Tomcat DoS in multipart upload
bugzilla·2025-06-16·CVSS 7.5
CVE-2025-48988 [HIGH] CVE-2025-48988 tomcat: Apache Tomcat DoS in multipart upload
CVE-2025-48988 tomcat: Apache Tomcat DoS in multipart upload
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.
Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
Discussion:
This issue has been addressed in the following products:
Red Hat JBoss Web Server 5.8 on RHEL 7
Red Hat JBoss Web Server 5.8 on RHEL 8
Red Hat JBoss Web Server 5.8 on RHEL 9
Via RHSA-2025:11695 https://access.redhat.com/errata/RHSA-2025:11695
---
This issue has been addressed in the following products:
Red Hat JBoss Web Server 5.8.5
Via RHSA-2025:11696 https://access.redhat.com/errata/RHSA-2025:11696
---
Bugzilla
CVE-2025-48988 tomcat: Apache Tomcat DoS in multipart upload [fedora-42]
bugzilla·2025-06-16·CVSS 7.5
CVE-2025-48988 [HIGH] CVE-2025-48988 tomcat: Apache Tomcat DoS in multipart upload [fedora-42]
CVE-2025-48988 tomcat: Apache Tomcat DoS in multipart upload [fedora-42]
More information about this security flaw is available in the following bug:
https://bugzilla.redhat.com/show_bug.cgi?id=2373015
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
Fixed in 9.0.106 onwards.
---
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
've
2025-06-16
Published