CVE-2025-52434

Severity
7.5HIGH
EPSS
0.5%
top 32.74%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 10

Description

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected. Users are recommended

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages4 packages

NVDapache/tomcat9.0.09.0.107
Mavenorg.apache.tomcat:tomcat-util9.0.0.M19.0.107+1
CVEListV5apache_software_foundation/apache_tomcat9.0.0.M19.0.106+1
Debiantomcat9< 9.0.107-0+deb11u1+3

🔴Vulnerability Details

4
GHSA
Apache Tomcat Utilities is vulnerable to resource exhaustion when using the APR/Native connector2025-07-10
OSV
Apache Tomcat Utilities is vulnerable to resource exhaustion when using the APR/Native connector2025-07-10
CVEList
Apache Tomcat: APR/Native Connector crash leading to DoS2025-07-10
OSV
CVE-2025-52434: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native c2025-07-10

📋Vendor Advisories

3
Red Hat
tomcat: Apache Tomcat denial of service2025-07-10
Debian
CVE-2025-52434: tomcat9 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race ...2025
Microsoft
smb: client: fix potential OOBs in smb2_parse_contexts()2024-02-13