CVE-2025-48989 – org.apache.tomcat:tomcat-coyote
Package
Manager: maven
Name: org.apache.tomcat:tomcat-coyote
Vulnerable Version: >=11.0.0-m1 <11.0.10 || >=10.1.0-m1 <10.1.44 || >=9.0.0.m1 <9.0.108
Severity
Level: High
CVSS v3.1: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS: 0.00177 pctl0.39535
Details
Apache Tomcat Improper Resource Shutdown or Release vulnerability Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected. Users are recommended to upgrade to one of versions 11.0.10, 10.1.44 or 9.0.108 which fix the issue.
Metadata
Created: 2025-08-13T15:30:34Z
Modified: 2025-08-22T20:52:22Z
Source: https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/08/GHSA-gqp3-2cvr-x8m3/GHSA-gqp3-2cvr-x8m3.json
CWE IDs: ["CWE-404"]
Alternative ID: GHSA-gqp3-2cvr-x8m3
Finding: F108
Auto approve: 1