icon

We found results for “

CVE-2025-48988

Good to know:

icon
icon

Date: June 16, 2025

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.

Severity Score

Severity Score

Weakness Type (CWE)

Allocation of Resources Without Limits or Throttling

CWE-770

Top Fix

icon

Upgrade Version

Upgrade to version org.apache.tomcat:tomcat-catalina:9.0.106;org.apache.tomcat:tomcat-catalina:10.1.42;org.apache.tomcat:tomcat-catalina:11.0.8;org.apache.tomcat:tomcat-catalina:11.0.8;org.apache.tomcat:tomcat-catalina:10.1.42;org.apache.tomcat:tomcat-catalina:9.0.106;org.apache.tomcat.embed:tomcat-embed-core:9.0.106;org.apache.tomcat.embed:tomcat-embed-core:10.1.42;org.apache.tomcat.embed:tomcat-embed-core:11.0.8;org.apache.tomcat.embed:tomcat-embed-core:11.0.8;org.apache.tomcat.embed:tomcat-embed-core:10.1.42;org.apache.tomcat.embed:tomcat-embed-core:9.0.106;https://github.com/apache/tomcat.git - 9.0.106;https://github.com/apache/tomcat.git - 10.1.42;https://github.com/apache/tomcat.git - 11.0.8

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): LOCAL
Attack Complexity (AC): LOW
Privileges Required (PR): LOW
User Interaction (UI): NONE
Scope (S): UNCHANGED
Confidentiality (C): LOW
Integrity (I): LOW
Availability (A): LOW

Do you need more information?

Contact Us