<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T14:14:14.366227+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:14177</id>
    <title>ALSA-2025:14177 — Important: tomcat security update</title>
    <updated>2026-10-03T14:14:14.402771+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:8: tomcat, AlmaLinux:8: tomcat-admin-webapps, AlmaLinux:8: tomcat-docs-webapp, AlmaLinux:8: tomcat-el-3.0-api, AlmaLinux:8: tomcat-jsp-2.3-api, AlmaLinux:8: tomcat-lib, AlmaLinux:8: tomcat-servlet-4.0-api, AlmaLinux:8: tomcat-webapps</p>
<p>Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.</p>
<p>Security Fix(es):</p>
<p>* tomcat: Apache Tomcat DoS in multipart upload (CVE-2025-48988)
  * tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources (CVE-2025-49125)
  * apache-commons-fileupload: Apache Commons FileUpload DoS via part headers (CVE-2025-48976)
  * tomcat: http/2 "MadeYouReset" DoS attack through HTTP/2 control frames (CVE-2025-48989)
  * tomcat: Apache Tomcat denial of service (CVE-2025-52520)
  * tomcat: Apache Tomcat denial of service (CVE-2025-52434)
  * tomcat: Apache Tomcat denial of service (CVE-2025-53506)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:14177"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-08952</id>
    <title>bdu:2025-08952</title>
    <updated>2026-10-03T14:14:14.402877+00:00</updated>
    <content>bdu:2025-08952</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-08952"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bit-tomcat-2025-53506</id>
    <title>BIT-tomcat-2025-53506 — Apache Tomcat: DoS via excessive h2 streams at connection start</title>
    <updated>2026-10-03T14:14:14.402902+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Bitnami: tomcat</p>
<p>Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams.</p>
<p>This issue affects Apache Tomcat: from 11.0.0 through 11.0.8, from 10.1.0 through 10.1.42, from 9.0.0 through 9.0.106.
The following versions were EOL at the time the CVE was created but are 
known to be affected: 8.5.0 through 8.5.100. Other EOL versions may also be affected.</p>
<p>Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bit-tomcat-2025-53506"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0584</id>
    <title>certfr-2025-avi-0584 — De multiples vulnérabilités ont été découvertes dans Apache Tomcat. Elles permettent à un attaquant de provoquer un dén…</title>
    <updated>2026-10-03T14:14:14.402941+00:00</updated>
    <content>certfr-2025-avi-0584</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2025-avi-0584"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2025-16618</id>
    <title>cnvd-2025-16618</title>
    <updated>2026-10-03T14:14:14.402963+00:00</updated>
    <content>cnvd-2025-16618</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2025-16618"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-259986</id>
    <title>EUVD-2026-259986</title>
    <updated>2026-10-03T14:14:14.402981+00:00</updated>
    <content>EUVD-2026-259986</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-259986"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-53506</id>
    <title>fkie_cve-2025-53506</title>
    <updated>2026-10-03T14:14:14.402997+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams.</p>
<p>This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.
The following versions were EOL at the time the CVE was created but are 
known to be affected: 8.5.0 through 8.5.100. Other EOL versions may also be affected.</p>
<p>Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-53506"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-25xr-qj8w-c4vf</id>
    <title>GHSA-25xr-qj8w-c4vf — Apache Tomcat Coyote vulnerable to Denial of Service via excessive HTTP/2 streams</title>
    <updated>2026-10-03T14:14:14.403035+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Maven: org.apache.tomcat:tomcat-coyote, Maven: org.apache.tomcat.embed:tomcat-embed-core</p>
<p>Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams.</p>
<p>This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100.</p>
<p>Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-25xr-qj8w-c4vf"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-1892</id>
    <title>OESA-2025-1892 — tomcat security update</title>
    <updated>2026-10-03T14:14:14.403080+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP4: tomcat</p>
<p>Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process.

Security Fix(es):</p>
<p>Concurrent Execution using Shared Resource with Improper Synchronization (&amp;apos;Race Condition&amp;apos;) vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.</p>
<p>This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106.</p>
<p>Users are recommended to upgrade to version 9.0.107, which fixes the issue.(CVE-2025-52434)</p>
<p>For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits.</p>
<p>This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.</p>
<p>Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.(CVE-2025-52520)</p>
<p>Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams.</p>
<p>This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.</p>
<p>Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.(CVE-202…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-1892"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15440-1</id>
    <title>openSUSE-SU-2025:15440-1 — tomcat-9.0.107-1.1 on GA media</title>
    <updated>2026-10-03T14:14:14.403139+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>tomcat-9.0.107-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15440-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:11695</id>
    <title>RHSA-2025:11695 — Red Hat Security Advisory: Red Hat JBoss Web Server 5.8.5 release and security update</title>
    <updated>2026-10-03T14:14:14.403166+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>apache-commons-fileupload: Apache Commons FileUpload DoS via part headers tomcat: Apache Tomcat DoS in multipart upload tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources tomcat: Apache Tomcat denial of service tomcat: Apache Tomcat denial of service tomcat: Apache Tomcat denial of service</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:11695"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:02745-1</id>
    <title>SUSE-SU-2025:02745-1 — Security update for tomcat</title>
    <updated>2026-10-03T14:14:14.403200+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for tomcat</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:02745-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-53506</id>
    <title>UBUNTU-CVE-2025-53506</title>
    <updated>2026-10-03T14:14:14.403239+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9, Ubuntu:Pro:20.04:LTS: tomcat9, Ubuntu:Pro:22.04:LTS: tomcat9, Ubuntu:24.04:LTS: tomcat10, Ubuntu:25.10: tomcat10, Ubuntu:25.10: tomcat11, Ubuntu:26.04:LTS: tomcat10, Ubuntu:26.04:LTS: tomcat11</p>
<p>Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-53506"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1468</id>
    <title>WID-SEC-W-2025-1468 — Apache Tomcat: Mehrere Schwachstellen ermöglichen Denial of Service</title>
    <updated>2026-10-03T14:14:14.403292+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache Tomcat ausnutzen, um einen Denial of Service Angriff durchzuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1468"/>
  </entry>
</feed>
