← Back to browse · API

CVE-2025-48988

Severity
HIGH
CVSS
7.5
EPSS
0.56286
Risk score
49.7
CISA KEV
No
PoC
No
Published
2025-06-16
Modified
2025-11-03
First seen
2026-08-07
Aliases
CNVD-2026-08773, EUVD-2025-18409, GHSA-H3GC-QFQQ-6H8F
Products
Apache Software Foundation:Apache Tomcat 10.1.0-M1 ≤10.1.41, Apache Software Foundation:Apache Tomcat 11.0.0-M1 ≤11.0.7, Apache Software Foundation:Apache Tomcat 8.5.0 ≤8.5.100, Apache Software Foundation:Apache Tomcat 9.0.0.M1 ≤9.0.105, Apache Tomcat >=10.1.0,<10.1.42, Apache Tomcat >=11.0.0,<11.0.8, Apache Tomcat >=9.0.0,<9.0.106
Sources
cnvd CNVD-2026-08773
euvd EUVD-2025-18409

Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.

References