Apache Tomcat Security Update – 19 August 2025

Apache has released a security update to address a vulnerability affecting multiple versions of Apache Tomcat.

The addressed vulnerability could allow the remote attacker to perform denial of service attacks on the affected products.

Apache Tomcat Denial of Service Vulnerability (CVE-2025-48989):

  • CVSS: 7.5
  • Attack Vector: Network
  • Attack Complexity: Low
  • Privileges Required: None
  • User Interaction: None
  • Consequences: Denial of Service

The affected versions:

  • Apache Tomcat 11.0.0-M1 to 11.0.9.
  • Apache Tomcat 10.1.0-M1 to 10.1.43.
  • Apache Tomcat 9.0.0.M1 to 9.0.107.
Vulnerabilities

CVE-2025-48989

Mitigations

The enterprise should deploy this patch as soon as the testing phase is completed.

Apache Tomcat Security Update

References