ZeroHour

CVE-2025-48988

mass

Unauthenticated resource-exhaustion DoS in Apache Tomcat

CVSS 3.1
7.5 high
EPSS
59%p99
Published
()
Modified
AI analysis

Apache Tomcat contains an allocation-of-resources-without-limits-or-throttling flaw (CWE-770) in which remote, unauthenticated network requests can cause the server to allocate resources without bound, resulting in a high-impact denial of service. An attacker needs no privileges or user interaction and can trigger the condition over the network, making exposed Tomcat instances easy targets for resource exhaustion. Users of Apache Tomcat 11.0.0-M1 through 11.0.7, 10.1.0-M1 through 10.1.41, 9.0.0.M1 through 9.0.105 are affected, as are users of the EOL 8.5.0 through 8.5.100 line and potentially other older EOL versions. There is no known public proof-of-concept and the flaw is not yet in CISA's KEV catalog, but EPSS assigns it a 59.5% probability of exploitation in the next 30 days (99th percentile), so active exploitation is considered likely in the near term.

What to do: Upgrade to Apache Tomcat 11.0.8, 10.1.42, or 9.0.106, which fix the issue; organizations on the EOL 8.5.x line should migrate to a supported, patched branch. Prioritize patching internet-facing Tomcat servers given the high EPSS score, and inventory deployments (including third-party applications bundling Tomcat) for affected versions.

Affected
Apache Tomcat11.0.0-M1 through 11.0.7
Apache Tomcat10.1.0-M1 through 10.1.41
Apache Tomcat9.0.0.M1 through 9.0.105
Apache Tomcat8.5.0 through 8.5.100 (EOL, known affected; other older EOL versions may also be affected)
Estimated exposure
masshundreds of thousands of internet-exposed Tomcat instances, likely more when internal deployments are counted — Tomcat is one of the most widely deployed Java application servers, and public internet scans (e.g., Shodan/Censys) typically enumerate hundreds of thousands of exposed instances, with far more in private/embedded deployments.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.

Vendors
apache
Products
tomcat
Weakness
CWE-770
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.