CVE-2025-48988
massUnauthenticated resource-exhaustion DoS in Apache Tomcat
Apache Tomcat contains an allocation-of-resources-without-limits-or-throttling flaw (CWE-770) in which remote, unauthenticated network requests can cause the server to allocate resources without bound, resulting in a high-impact denial of service. An attacker needs no privileges or user interaction and can trigger the condition over the network, making exposed Tomcat instances easy targets for resource exhaustion. Users of Apache Tomcat 11.0.0-M1 through 11.0.7, 10.1.0-M1 through 10.1.41, 9.0.0.M1 through 9.0.105 are affected, as are users of the EOL 8.5.0 through 8.5.100 line and potentially other older EOL versions. There is no known public proof-of-concept and the flaw is not yet in CISA's KEV catalog, but EPSS assigns it a 59.5% probability of exploitation in the next 30 days (99th percentile), so active exploitation is considered likely in the near term.
What to do: Upgrade to Apache Tomcat 11.0.8, 10.1.42, or 9.0.106, which fix the issue; organizations on the EOL 8.5.x line should migrate to a supported, patched branch. Prioritize patching internet-facing Tomcat servers given the high EPSS score, and inventory deployments (including third-party applications bundling Tomcat) for affected versions.
| Apache Tomcat | 11.0.0-M1 through 11.0.7 |
| Apache Tomcat | 10.1.0-M1 through 10.1.41 |
| Apache Tomcat | 9.0.0.M1 through 9.0.105 |
| Apache Tomcat | 8.5.0 through 8.5.100 (EOL, known affected; other older EOL versions may also be affected) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
- Vendors
- apache
- Products
- tomcat
- Weakness
- CWE-770
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.