CVE-2025-52434
published 2025-07-10CVE-2025-52434: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector…
PriorityP346high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.82%
76.3th percentile
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.
This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions
may also be affected.
Users are recommended to upgrade to version 9.0.107, which fixes the issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | >= 9.0.0 < 9.0.107 | 9.0.107 |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.0.M1 – 9.0.106 | — |
| debian | tomcat9 | < tomcat9 9.0.70-2 (bookworm) | tomcat9 9.0.70-2 (bookworm) |
| msrc | cbl2_kernel_5.15.148.2-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_kernel_5.15.153.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_msrc8.0HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tomcat: Apache Tomcat denial of service
vendor_redhat·2025-07-10·CVSS 7.5
CVE-2025-52434 [HIGH] CWE-362 tomcat: Apache Tomcat denial of service
tomcat: Apache Tomcat denial of service
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.
This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions
may also be affected.
Users are recommended to upgrade to version 9.0.107, which fixes the issue.
A denial of service flaw was found in Apache Tomcat. A race condition during connection closure could trigger a JVM crash when using the APR/Native connector, leading to a denial of service. This issue was
Debian
CVE-2025-52434: tomcat9 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race ...
vendor_debian·2025·CVSS 7.5
CVE-2025-52434 [HIGH] CVE-2025-52434: tomcat9 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race ...
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 9.0.107, which fixes the issue.
Scope: local
bookworm: resolved (fixed in 9.0.70-2)
bullseye: resolved (fixed in 9.0.107-0+deb11u1)
forky: resolved (fixed in 9.0.70-2)
sid: resolved (fixed in 9.0.70-2)
trixie: resolved (fixed in 9.0.70-2)
Microsoft
smb: client: fix potential OOBs in smb2_parse_contexts()
vendor_msrc·2024-02-13·CVSS 8.0
CVE-2023-52434 [HIGH] CWE-119 smb: client: fix potential OOBs in smb2_parse_contexts()
smb: client: fix potential OOBs in smb2_parse_contexts()
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
Linux: Linux
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://lear
GHSA
Apache Tomcat Utilities is vulnerable to resource exhaustion when using the APR/Native connector
ghsa·2025-07-10
CVE-2025-52434 [MEDIUM] CWE-362 Apache Tomcat Utilities is vulnerable to resource exhaustion when using the APR/Native connector
Apache Tomcat Utilities is vulnerable to resource exhaustion when using the APR/Native connector
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.
This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 9.0.107, which fixes the issue.
OSV
Apache Tomcat Utilities is vulnerable to resource exhaustion when using the APR/Native connector
osv·2025-07-10
CVE-2025-52434 [MEDIUM] Apache Tomcat Utilities is vulnerable to resource exhaustion when using the APR/Native connector
Apache Tomcat Utilities is vulnerable to resource exhaustion when using the APR/Native connector
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.
This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 9.0.107, which fixes the issue.
OSV
CVE-2025-52434: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native c
osv·2025-07-10·CVSS 7.5
CVE-2025-52434 [HIGH] CVE-2025-52434: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native c
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 9.0.107, which fixes the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-10
Published