CVE-2025-48989 Details
Description
Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected. Users are recommended to upgrade to one of versions 11.0.10, 10.1.44 or 9.0.108 which fix the issue.
A denial-of-service vulnerability has been identified in Apache Tomcat's HTTP/2 implementation, affecting versions 11.0.0-M1 prior to 11.0.9, 10.1.0-M1 prior to 10.1.43, and 9.0.0-M1 prior to 9.0.107. This vulnerability is susceptible to the 'made you reset' attack, which can lead to an OutOfMemoryError. Older, end-of-life versions may also be affected.
Users should upgrade to Apache Tomcat 11.0.10 or later, 10.1.44 or later, or 9.0.108 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 13, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-032379.html | siemens-SADP | |
| https://www.kb.cert.org/vuls/id/767506 | CVE | |
| http://www.openwall.com/lists/oss-security/2025/08/13/2 | CVE | |
| https://lists.apache.org/thread/9ydfg0xr0tchmglcprhxgwhj0hfwxlyf | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache tomcat | >= 9.0.1, < 9.0.108 >= 10.0.0, < 10.1.44 >= 11.0.0, < 11.0.10 9.0.0 milestone1 9.0.0 milestone10 9.0.0 milestone11 9.0.0 milestone12 9.0.0 milestone13 9.0.0 milestone14 9.0.0 milestone15 9.0.0 milestone16 9.0.0 milestone17 9.0.0 milestone18 9.0.0 milestone19 9.0.0 milestone2 9.0.0 milestone20 9.0.0 milestone21 9.0.0 milestone22 9.0.0 milestone23 9.0.0 milestone24 9.0.0 milestone25 9.0.0 milestone26 9.0.0 milestone27 9.0.0 milestone3 9.0.0 milestone4 9.0.0 milestone5 9.0.0 milestone6 9.0.0 milestone7 9.0.0 milestone8 9.0.0 milestone9 |
CPE
Remediation
| |
Change History
9 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 17, 2026 | CVE Modified | siemens-SADP |
| May 12, 2026 | CVE Modified | siemens-SADP |
| Nov 4, 2025 | CVE Modified | CVE |
| Nov 3, 2025 | CVE Modified | CVE |
| Aug 18, 2025 | Initial Analysis | [email protected] |
| Aug 13, 2025 | CVE Modified | CISA-ADP |
| Aug 13, 2025 | New CVE Received | [email protected] |