<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:51:59.047340+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:14177</id>
    <title>ALSA-2025:14177 — Important: tomcat security update</title>
    <updated>2026-10-02T19:51:59.289010+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: tomcat, AlmaLinux:8: tomcat-admin-webapps, AlmaLinux:8: tomcat-docs-webapp, AlmaLinux:8: tomcat-el-3.0-api, AlmaLinux:8: tomcat-jsp-2.3-api, AlmaLinux:8: tomcat-lib, AlmaLinux:8: tomcat-servlet-4.0-api, AlmaLinux:8: tomcat-webapps</p>
<p>Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.</p>
<p>Security Fix(es):</p>
<p>* tomcat: Apache Tomcat DoS in multipart upload (CVE-2025-48988)
  * tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources (CVE-2025-49125)
  * apache-commons-fileupload: Apache Commons FileUpload DoS via part headers (CVE-2025-48976)
  * tomcat: http/2 "MadeYouReset" DoS attack through HTTP/2 control frames (CVE-2025-48989)
  * tomcat: Apache Tomcat denial of service (CVE-2025-52520)
  * tomcat: Apache Tomcat denial of service (CVE-2025-52434)
  * tomcat: Apache Tomcat denial of service (CVE-2025-53506)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:14177"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-07526</id>
    <title>bdu:2025-07526</title>
    <updated>2026-10-02T19:51:59.289090+00:00</updated>
    <content>bdu:2025-07526</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-07526"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-tomcat-2025-48988</id>
    <title>BIT-tomcat-2025-48988 — Apache Tomcat: FileUpload large number of parts with headers DoS</title>
    <updated>2026-10-02T19:51:59.289108+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: tomcat</p>
<p>Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.</p>
<p>This issue affects Apache Tomcat: from 11.0.0 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.0 through 9.0.105.
The following versions were EOL at the time the CVE was created but are 
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions 
may also be affected.</p>
<p>Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-tomcat-2025-48988"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0516</id>
    <title>certfr-2025-avi-0516 — De multiples vulnérabilités ont été découvertes dans Apache Tomcat. Elles permettent à un attaquant de provoquer un dén…</title>
    <updated>2026-10-02T19:51:59.289133+00:00</updated>
    <content>certfr-2025-avi-0516</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0516"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-257967</id>
    <title>EUVD-2026-257967</title>
    <updated>2026-10-02T19:51:59.289149+00:00</updated>
    <content>EUVD-2026-257967</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-257967"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-48988</id>
    <title>fkie_cve-2025-48988</title>
    <updated>2026-10-02T19:51:59.289160+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.</p>
<p>This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.
The following versions were EOL at the time the CVE was created but are 
known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions 
may also be affected.</p>
<p>Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-48988"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-h3gc-qfqq-6h8f</id>
    <title>GHSA-h3gc-qfqq-6h8f — Apache Tomcat - DoS in multipart upload</title>
    <updated>2026-10-02T19:51:59.289183+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat:tomcat-catalina, Maven: org.apache.tomcat.embed:tomcat-embed-core</p>
<p>Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.</p>
<p>This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected.</p>
<p>Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-h3gc-qfqq-6h8f"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/jvndb-2025-000044</id>
    <title>jvndb-2025-000044</title>
    <updated>2026-10-02T19:51:59.289213+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Multiple Apache products provided by The Apache Software Foundation contain vulnerabilities listed below.
&lt;ul&gt;&lt;li&gt;Allocation of resources without limits or throttling (CWE-770) - CVE-2025-48976, CVE-2025-48988&lt;/li&gt;&lt;/ul&gt;
TERASOLUNA Framework Security Team of NTT DATA Group Corporation reported this vulnerability to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/jvndb-2025-000044"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1644</id>
    <title>OESA-2025-1644 — tomcat security update</title>
    <updated>2026-10-02T19:51:59.289233+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: tomcat, openEuler:22.03-LTS-SP3: tomcat, openEuler:22.03-LTS-SP4: tomcat, openEuler:24.03-LTS: tomcat, openEuler:24.03-LTS-SP1: tomcat</p>
<p>Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process.

Security Fix(es):</p>
<p>Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.</p>
<p>This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.</p>
<p>Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.(CVE-2025-48988)</p>
<p>Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowing those security constraints to be bypassed.</p>
<p>This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105.</p>
<p>Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.(CVE-2025-49125)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1644"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15301-1</id>
    <title>openSUSE-SU-2025:15301-1 — tomcat-9.0.106-1.1 on GA media</title>
    <updated>2026-10-02T19:51:59.289276+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat-9.0.106-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15301-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ppsa-2026-001</id>
    <title>PPSA-2026-001 — Pilz: Multiple Vulnerabilities affecting the PIT User Authentication Service</title>
    <updated>2026-10-02T19:51:59.289295+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>**PIT User Authentication Service is part of the operating mode selection and access permission system PITmode.** The PIT User Authentication Service is affected by multiple vulnerabilities in included third-party components.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ppsa-2026-001"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:11695</id>
    <title>RHSA-2025:11695 — Red Hat Security Advisory: Red Hat JBoss Web Server 5.8.5 release and security update</title>
    <updated>2026-10-02T19:51:59.289313+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>apache-commons-fileupload: Apache Commons FileUpload DoS via part headers tomcat: Apache Tomcat DoS in multipart upload tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources tomcat: Apache Tomcat denial of service tomcat: Apache Tomcat denial of service tomcat: Apache Tomcat denial of service</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:11695"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02214-1</id>
    <title>SUSE-SU-2025:02214-1 — Security update for tomcat</title>
    <updated>2026-10-02T19:51:59.289335+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02214-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-48988</id>
    <title>UBUNTU-CVE-2025-48988</title>
    <updated>2026-10-02T19:51:59.289350+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:14.04:LTS: tomcat6, Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:Pro:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9, Ubuntu:Pro:20.04:LTS: tomcat9, Ubuntu:Pro:22.04:LTS: tomcat9, Ubuntu:24.04:LTS: tomcat10, Ubuntu:25.10: tomcat10 and 3 more</p>
<p>Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-48988"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1335</id>
    <title>WID-SEC-W-2025-1335 — Apache Tomcat: Mehrere Schwachstellen</title>
    <updated>2026-10-02T19:51:59.289386+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in Apache Tomcat ausnutzen, um einen Denial of Service Angriff durchzuführen, um Code auszuführen und um Sicherheitsmechanismen zu umgehen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1335"/>
  </entry>
</feed>
