#VU111162 Resource exhaustion in Apache Tomcat - CVE-2025-48976
Published: June 16, 2025 / Updated: December 15, 2025
Apache Tomcat
Apache Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to Apache Commons FileUpload provided a hard-coded limit of 10kB for the size of the headers associated with a multipart request. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Remediation
External links
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.8
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.42
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.106
- https://github.com/apache/tomcat/commit/74f69ffaf61e54c727603e7e831fe20f0ac5d2a7
- https://github.com/apache/tomcat/commit/667ddd76e2a0e762f3a784d86f0d25e7fd7cdb86
- https://github.com/apache/tomcat/commit/97790a35a27d236fa053e660676c3f8196284d93
- https://lists.apache.org/thread/3c3q2hv3vv7bz15p4vxx9dpbqbrzpyvm