ID:11725 - Exploit for Resource exhaustion in Apache Tomcat - CVE-2025-48976
Published: June 27, 2025
Apache Tomcat
Link to public exploit:
Vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to Apache Commons FileUpload provided a hard-coded limit of 10kB for the size of the headers associated with a multipart request. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.