#VU112276 Resource exhaustion in Apache Tomcat - CVE-2025-53506
Published: July 4, 2025 / Updated: July 10, 2025
Apache Tomcat
Apache Foundation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling excessive HTTP/2 streams. A remote attacker can trigger resource exhaustion and perform a denial of service (DoS) attack.
Remediation
External links
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.107
- https://github.com/apache/tomcat/commit/434772930f362145516dd60681134e7f0cf8115b
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.43
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.9
- https://lists.apache.org/thread/tfjqf1odwql63sb40lqpb7dvlffk15t7
- https://lists.apache.org/thread/cdfmz3l1blkbgpg9jdn9tg9rlv2bzwj5