CVE-2025-48989
published 2025-08-13CVE-2025-48989: Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat…
PriorityP351high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.51%
88.0th percentile
Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected.
Users are recommended to upgrade to one of versions 11.0.10, 10.1.44 or 9.0.108 which fix the issue.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | >= 10.0.0 < 10.1.44 | 10.1.44 |
| apache | tomcat | >= 11.0.0 < 11.0.10 | 11.0.10 |
| apache | tomcat | >= 9.0.1 < 9.0.108 | 9.0.108 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.43 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.9 | — |
| apache_software_foundation | apache_tomcat | 9.0.0.M1 – 9.0.107 | — |
| debian | tomcat10 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
| debian | tomcat11 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Siebel CRM Risk Matrix: Application Interface (Apache Tomcat) — CVE-2025-48989
vendor_oracle·2026-01-15·CVSS 7.5
CVE-2025-48989 [HIGH] Oracle Oracle Siebel CRM Risk Matrix: Application Interface (Apache Tomcat) — CVE-2025-48989
Oracle Oracle Siebel CRM Risk Matrix: Application Interface (Apache Tomcat) vulnerability
CVE: CVE-2025-48989
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2026 (JAN 2026)
Oracle
Oracle Oracle Commerce Risk Matrix: Tools And Frameworks, Content Acquisition System, Platform Services (Apache Tomcat) — CVE-2025-48989
vendor_oracle·2025-10-15·CVSS 4.9
CVE-2025-48989 [HIGH] Oracle Oracle Commerce Risk Matrix: Tools And Frameworks, Content Acquisition System, Platform Services (Apache Tomcat) — CVE-2025-48989
Oracle Oracle Commerce Risk Matrix: Tools And Frameworks, Content Acquisition System, Platform Services (Apache Tomcat) vulnerability
CVE: CVE-2025-48989
CVSS: 4.9
Protocol: HTTP/2
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Red Hat
upstream:
vendor_redhat·2025-08-13·CVSS 7.5
CVE-2025-8671 [HIGH] upstream:
upstream:
A mismatch caused by client-triggered server-sent stream resets between HTTP/2 specifications and the internal architectures of some HTTP/2 implementations may result in excessive server resource consumption leading to denial-of-service (DoS). By opening streams and then rapidly triggering the server to reset them—using malformed frames or flow control errors—an attacker can exploit incorrect stream accounting. Streams reset by the server are considered closed at the protocol level, even though backend processing continues. This allows a client to cause the server to handle an unbounded number of concurrent streams on a single connection. This CVE will be updated as affected product details are released.
A flaw was found in multiple implementations of HTTP/2 where malformed cli
Red Hat
tomcat: http/2 "MadeYouReset" DoS attack through HTTP/2 control frames
vendor_redhat·2025-08-13·CVSS 7.5
CVE-2025-48989 [HIGH] CWE-400 tomcat: http/2 "MadeYouReset" DoS attack through HTTP/2 control frames
tomcat: http/2 "MadeYouReset" DoS attack through HTTP/2 control frames
Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected.
Users are recommended to upgrade to one of versions 11.0.10, 10.1.44 or 9.0.108 which fix the issue.
A flaw was found in Apache Tomcat where malformed client requests can trigger server-side stream resets without triggering abuse counters. This issue, referred to as the "MadeYouReset" attack, allows malicious clients to induce excessive server workload by repeatedly causing server-side stream aborts. While not a protocol bug, th
Debian
CVE-2025-48989: tomcat10 - Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat...
vendor_debian·2025·CVSS 7.5
CVE-2025-48989 [HIGH] CVE-2025-48989: tomcat10 - Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat...
Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected. Users are recommended to upgrade to one of versions 11.0.10, 10.1.44 or 9.0.108 which fix the issue.
Scope: local
bookworm: resolved (fixed in 10.1.52-1~deb12u1)
forky: resolved (fixed in 10.1.52-1)
sid: resolved (fixed in 10.1.52-1)
trixie: resolved (fixed in 10.1.52-1~deb13u1)
OSV
Apache Tomcat Improper Resource Shutdown or Release vulnerability
osv·2025-08-13
CVE-2025-48989 [HIGH] Apache Tomcat Improper Resource Shutdown or Release vulnerability
Apache Tomcat Improper Resource Shutdown or Release vulnerability
Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected.
Users are recommended to upgrade to one of versions 11.0.10, 10.1.44 or 9.0.108 which fix the issue.
GHSA
Apache Tomcat Improper Resource Shutdown or Release vulnerability
ghsa·2025-08-13
CVE-2025-48989 [HIGH] CWE-404 Apache Tomcat Improper Resource Shutdown or Release vulnerability
Apache Tomcat Improper Resource Shutdown or Release vulnerability
Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected.
Users are recommended to upgrade to one of versions 11.0.10, 10.1.44 or 9.0.108 which fix the issue.
OSV
CVE-2025-48989: Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack
osv·2025-08-13·CVSS 7.5
CVE-2025-48989 [HIGH] CVE-2025-48989: Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack
Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected. Users are recommended to upgrade to one of versions 11.0.10, 10.1.44 or 9.0.108 which fix the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-08-13
Published