Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected.
Users are recommended to upgrade to one of versions 11.0.10, 10.1.44 or 9.0.108 which fix the issue.
Metrics
Affected Vendors & Products
References
History
Thu, 14 Aug 2025 06:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Apache
Apache tomcat Redhat Redhat jboss Enterprise Web Server |
|
Weaknesses | CWE-400 | |
CPEs | cpe:/a:redhat:jboss_enterprise_web_server:6.1 cpe:/a:redhat:jboss_enterprise_web_server:6.1::el10 cpe:/a:redhat:jboss_enterprise_web_server:6.1::el8 cpe:/a:redhat:jboss_enterprise_web_server:6.1::el9 |
|
Vendors & Products |
Apache
Apache tomcat Redhat Redhat jboss Enterprise Web Server |
|
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Wed, 13 Aug 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Wed, 13 Aug 2025 12:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected. Users are recommended to upgrade to one of versions 11.0.10, 10.1.44 or 9.0.108 which fix the issue. | |
Title | Apache Tomcat: h2 DoS - Made You Reset | |
Weaknesses | CWE-404 | |
References |
|

Status: PUBLISHED
Assigner: apache
Published: 2025-08-13T12:11:26.124Z
Updated: 2025-08-13T19:56:35.999Z
Reserved: 2025-05-29T15:25:37.243Z
Link: CVE-2025-48989

Updated: 2025-08-13T18:37:19.170Z

Status : Awaiting Analysis
Published: 2025-08-13T13:15:34.153
Modified: 2025-08-13T20:15:30.423
Link: CVE-2025-48989
