CVE-2025-52520
published 2025-07-10CVE-2025-52520: For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits. This…
PriorityP347high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.96%
78.1th percentile
For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions
may also be affected.
Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | >= 10.1.0 < 10.1.43 | 10.1.43 |
| apache | tomcat | >= 11.0.0 < 11.0.9 | 11.0.9 |
| apache | tomcat | >= 9.0.0 < 9.0.107 | 9.0.107 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.42 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.8 | — |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.0.M1 – 9.0.106 | — |
| debian | tomcat10 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
| debian | tomcat11 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_redhat7.5HIGH
vendor_oracle6.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Graph Server and Client Risk Matrix: Install (Apache Tomcat) — CVE-2025-52520
vendor_oracle·2025-10-15·CVSS 6.5
CVE-2025-52520 [HIGH] Oracle Oracle Graph Server and Client Risk Matrix: Install (Apache Tomcat) — CVE-2025-52520
Oracle Oracle Graph Server and Client Risk Matrix: Install (Apache Tomcat) vulnerability
CVE: CVE-2025-52520
CVSS: 6.5
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2025 (OCT 2025)
Red Hat
tomcat: Apache Tomcat denial of service
vendor_redhat·2025-07-10·CVSS 7.5
CVE-2025-52520 [HIGH] CWE-190 tomcat: Apache Tomcat denial of service
tomcat: Apache Tomcat denial of service
For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions
may also be affected.
Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.
A denial of service flaw was found in Apache Tomcat. For some unlikely configurations of multipart upload, an integer overflow vulnerability may lead to a denial of service via bypassing size limits.
Mitigation: Mit
Debian
CVE-2025-52520: tomcat10 - For some unlikely configurations of multipart upload, an Integer Overflow vulner...
vendor_debian·2025·CVSS 7.5
CVE-2025-52520 [HIGH] CVE-2025-52520: tomcat10 - For some unlikely configurations of multipart upload, an Integer Overflow vulner...
For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.
Scope: local
bookworm: resolved (fixed in 10.1.52-1~deb12u1)
forky: resolved (fixed in 10.1.46-1)
sid: resolved (fixed in 10.1.46-1)
trixie: resolved (fixed in 10.1.52-1~deb13u1)
OSV
Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits
osv·2025-07-10
CVE-2025-52520 [HIGH] Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits
Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits
For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.
GHSA
Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits
ghsa·2025-07-10
CVE-2025-52520 [HIGH] CWE-190 Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits
Apache Tomcat Catalina is vulnerable to DoS attack through bypassing of size limits
For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected.
Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.
OSV
CVE-2025-52520: For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size lim
osv·2025-07-10·CVSS 7.5
CVE-2025-52520 [HIGH] CVE-2025-52520: For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size lim
For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-07-10
Published