<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 20:29:29 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:14177 — Important: tomcat security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:14177</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: tomcat, AlmaLinux:8: tomcat-admin-webapps, AlmaLinux:8: tomcat-docs-webapp, AlmaLinux:8: tomcat-el-3.0-api, AlmaLinux:8: tomcat-jsp-2.3-api, AlmaLinux:8: tomcat-lib, AlmaLinux:8: tomcat-servlet-4.0-api, AlmaLinux:8: tomcat-webapps&lt;/p&gt;
&lt;p&gt;Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tomcat: Apache Tomcat DoS in multipart upload (CVE-2025-48988)
  * tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources (CVE-2025-49125)
  * apache-commons-fileupload: Apache Commons FileUpload DoS via part headers (CVE-2025-48976)
  * tomcat: http/2 &amp;#34;MadeYouReset&amp;#34; DoS attack through HTTP/2 control frames (CVE-2025-48989)
  * tomcat: Apache Tomcat denial of service (CVE-2025-52520)
  * tomcat: Apache Tomcat denial of service (CVE-2025-52434)
  * tomcat: Apache Tomcat denial of service (CVE-2025-53506)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:8: tomcat, AlmaLinux:8: tomcat-admin-webapps, AlmaLinux:8: tomcat-docs-webapp, AlmaLinux:8: tomcat-el-3.0-api, AlmaLinux:8: tomcat-jsp-2.3-api, AlmaLinux:8: tomcat-lib, AlmaLinux:8: tomcat-servlet-4.0-api, AlmaLinux:8: tomcat-webapps&lt;/p&gt;
&lt;p&gt;Apache Tomcat is a servlet container for the Java Servlet and JavaServer Pages (JSP) technologies.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* tomcat: Apache Tomcat DoS in multipart upload (CVE-2025-48988)
  * tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources (CVE-2025-49125)
  * apache-commons-fileupload: Apache Commons FileUpload DoS via part headers (CVE-2025-48976)
  * tomcat: http/2 &amp;#34;MadeYouReset&amp;#34; DoS attack through HTTP/2 control frames (CVE-2025-48989)
  * tomcat: Apache Tomcat denial of service (CVE-2025-52520)
  * tomcat: Apache Tomcat denial of service (CVE-2025-52434)
  * tomcat: Apache Tomcat denial of service (CVE-2025-53506)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:14177</guid>
    </item>
    <item>
      <title>bdu:2025-08954</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-08954</link>
      <description>bdu:2025-08954</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-08954</guid>
    </item>
    <item>
      <title>BIT-tomcat-2025-52434 — Apache Tomcat: APR/Native Connector crash leading to DoS</title>
      <link>https://cve.radiocsirt.org/vuln/bit-tomcat-2025-52434</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;Concurrent Execution using Shared Resource with Improper Synchronization (&amp;#39;Race Condition&amp;#39;) vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 9.0.0 through 9.0.106.
The following versions were EOL at the time the CVE was created but are 
known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions 
may also be affected.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 9.0.107, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;Concurrent Execution using Shared Resource with Improper Synchronization (&amp;#39;Race Condition&amp;#39;) vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 9.0.0 through 9.0.106.
The following versions were EOL at the time the CVE was created but are 
known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions 
may also be affected.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 9.0.107, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-tomcat-2025-52434</guid>
    </item>
    <item>
      <title>certfr-2025-avi-0584 — De multiples vulnérabilités ont été découvertes dans Apache Tomcat. Elles permettent à un attaquant de provoquer un dén…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2025-avi-0584</link>
      <description>certfr-2025-avi-0584</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2025-avi-0584</guid>
    </item>
    <item>
      <title>cnvd-2025-16616</title>
      <link>https://cve.radiocsirt.org/vuln/cnvd-2025-16616</link>
      <description>cnvd-2025-16616</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cnvd-2025-16616</guid>
    </item>
    <item>
      <title>EUVD-2026-259980</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-259980</link>
      <description>EUVD-2026-259980</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-259980</guid>
    </item>
    <item>
      <title>fkie_cve-2025-52434</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-52434</link>
      <description>&lt;p&gt;Concurrent Execution using Shared Resource with Improper Synchronization (&amp;#39;Race Condition&amp;#39;) vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106.
The following versions were EOL at the time the CVE was created but are 
known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions 
may also be affected.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 9.0.107, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Concurrent Execution using Shared Resource with Improper Synchronization (&amp;#39;Race Condition&amp;#39;) vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106.
The following versions were EOL at the time the CVE was created but are 
known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions 
may also be affected.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 9.0.107, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-52434</guid>
    </item>
    <item>
      <title>GHSA-4j3c-42xv-3f84 — Apache Tomcat is vulnerable to resource exhaustion when using the APR/Native connector</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-4j3c-42xv-3f84</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat-coyote, Maven: org.apache.tomcat.embed:tomcat-embed-core&lt;/p&gt;
&lt;p&gt;Concurrent Execution using Shared Resource with Improper Synchronization (&amp;#39;Race Condition&amp;#39;) vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106.  The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 9.0.107, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Maven: org.apache.tomcat:tomcat-coyote, Maven: org.apache.tomcat.embed:tomcat-embed-core&lt;/p&gt;
&lt;p&gt;Concurrent Execution using Shared Resource with Improper Synchronization (&amp;#39;Race Condition&amp;#39;) vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106.  The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 9.0.107, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-4j3c-42xv-3f84</guid>
    </item>
    <item>
      <title>NCSC-2026-0034 — Kwetsbaarheden verholpen in Atlassian producten</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0034</link>
      <description>NCSC-2026-0034</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0034</guid>
    </item>
    <item>
      <title>OESA-2025-1892 — tomcat security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-1892</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: tomcat&lt;/p&gt;
&lt;p&gt;Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Concurrent Execution using Shared Resource with Improper Synchronization (&amp;amp;apos;Race Condition&amp;amp;apos;) vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 9.0.107, which fixes the issue.(CVE-2025-52434)&lt;/p&gt;
&lt;p&gt;For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.(CVE-2025-52520)&lt;/p&gt;
&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.(CVE-202…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:20.03-LTS-SP4: tomcat&lt;/p&gt;
&lt;p&gt;Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Concurrent Execution using Shared Resource with Improper Synchronization (&amp;amp;apos;Race Condition&amp;amp;apos;) vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 9.0.107, which fixes the issue.(CVE-2025-52434)&lt;/p&gt;
&lt;p&gt;For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.(CVE-2025-52520)&lt;/p&gt;
&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.&lt;/p&gt;
&lt;p&gt;Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.(CVE-202…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-1892</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15440-1 — tomcat-9.0.107-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15440-1</link>
      <description>&lt;p&gt;tomcat-9.0.107-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat-9.0.107-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15440-1</guid>
    </item>
    <item>
      <title>RHSA-2025:11695 — Red Hat Security Advisory: Red Hat JBoss Web Server 5.8.5 release and security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:11695</link>
      <description>&lt;p&gt;apache-commons-fileupload: Apache Commons FileUpload DoS via part headers tomcat: Apache Tomcat DoS in multipart upload tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources tomcat: Apache Tomcat denial of service tomcat: Apache Tomcat denial of service tomcat: Apache Tomcat denial of service&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;apache-commons-fileupload: Apache Commons FileUpload DoS via part headers tomcat: Apache Tomcat DoS in multipart upload tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources tomcat: Apache Tomcat denial of service tomcat: Apache Tomcat denial of service tomcat: Apache Tomcat denial of service&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:11695</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:1058-1 — Security update for tomcat</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:1058-1</link>
      <description>&lt;p&gt;Security update for tomcat&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:1058-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-52434</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-52434</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9, Ubuntu:Pro:20.04:LTS: tomcat9, Ubuntu:Pro:22.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;Concurrent Execution using Shared Resource with Improper Synchronization (&amp;#39;Race Condition&amp;#39;) vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 9.0.107, which fixes the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9, Ubuntu:Pro:20.04:LTS: tomcat9, Ubuntu:Pro:22.04:LTS: tomcat9&lt;/p&gt;
&lt;p&gt;Concurrent Execution using Shared Resource with Improper Synchronization (&amp;#39;Race Condition&amp;#39;) vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 9.0.107, which fixes the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-52434</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-1468 — Apache Tomcat: Mehrere Schwachstellen ermöglichen Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1468</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache Tomcat ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Apache Tomcat ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-1468</guid>
    </item>
  </channel>
</rss>
