CVE-2025-53506

Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.
References
Link Resource
https://lists.apache.org/thread/p09775q0rd185m6zz98krg0fp45j8kr0 Issue Tracking Mailing List Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*

History

08 Aug 2025, 13:15

Type Values Removed Values Added
Summary (en) Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue. (en) Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.

07 Aug 2025, 12:15

Type Values Removed Values Added
Summary (en) Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue. (en) Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.9, 10.1.43 or 9.0.107, which fix the issue.
References () https://lists.apache.org/thread/p09775q0rd185m6zz98krg0fp45j8kr0 - Vendor Advisory, Issue Tracking, Mailing List () https://lists.apache.org/thread/p09775q0rd185m6zz98krg0fp45j8kr0 - Issue Tracking, Mailing List, Vendor Advisory

29 Jul 2025, 18:35

Type Values Removed Values Added
CPE cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
First Time Apache
Apache tomcat
References () https://lists.apache.org/thread/p09775q0rd185m6zz98krg0fp45j8kr0 - () https://lists.apache.org/thread/p09775q0rd185m6zz98krg0fp45j8kr0 - Vendor Advisory, Issue Tracking, Mailing List

11 Jul 2025, 14:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
Summary
  • (es) Vulnerabilidad de consumo incontrolado de recursos en Apache Tomcat si un cliente HTTP/2 no reconoce el marco de configuración inicial que reduce el máximo de transmisiones simultáneas permitidas. Este problema afecta a Apache Tomcat: de 11.0.0-M1 a 11.0.8, de 10.1.0-M1 a 10.1.42, y de 9.0.0.M1 a 9.0.106. Se recomienda actualizar a las versiones 11.0.9, 10.1.43 o 9.0.107, que solucionan el problema.

10 Jul 2025, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-10 20:15

Updated : 2025-08-08 13:15


NVD link : CVE-2025-53506

Mitre link : CVE-2025-53506

CVE.ORG link : CVE-2025-53506


JSON object : View

Products Affected

apache

  • tomcat
CWE
CWE-400

Uncontrolled Resource Consumption