[ALSA-2025:14178] Important: tomcat9 security update
Type:
security
Severity:
important
Release date:
2025-08-22
Description:
Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process. Tomcat is developed in an open and participatory environment and released under the Apache Software License version 2.0. Tomcat is intended to be a collaboration of the best-of-breed developers from around the world. Security Fix(es): * tomcat: Apache Tomcat DoS in multipart upload (CVE-2025-48988) * tomcat: Apache Tomcat: Security constraint bypass for pre/post-resources (CVE-2025-49125) * apache-commons-fileupload: Apache Commons FileUpload DoS via part headers (CVE-2025-48976) * tomcat: http/2 "MadeYouReset" DoS attack through HTTP/2 control frames (CVE-2025-48989) * tomcat: Apache Tomcat denial of service (CVE-2025-52520) * tomcat: Apache Tomcat denial of service (CVE-2025-52434) * tomcat: Apache Tomcat denial of service (CVE-2025-53506) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
noarch tomcat9-admin-webapps-9.0.87-5.el10_0.3.noarch.rpm 2d7520d20ea7b78a6fa23800e3a0c5baaa1de8a082f02be669b157955db65a0d
noarch tomcat9-el-3.0-api-9.0.87-5.el10_0.3.noarch.rpm 405974ad48200fe52a4f69963b64323d79694de9d002789aa9f09d751ba53abd
noarch tomcat9-docs-webapp-9.0.87-5.el10_0.3.noarch.rpm 52e8a6c6399b38fe760681235b8919d0b1e4e6d9bdf845ccf75c5f2474690d47
noarch tomcat9-lib-9.0.87-5.el10_0.3.noarch.rpm 595546b10039ab07d6daa5eebff15803444a0d88923275e03c6a0b9508d5a5a9
noarch tomcat9-jsp-2.3-api-9.0.87-5.el10_0.3.noarch.rpm 98d12f79159a9233bf027574c3e05b6d1a90cc9aaa9d5d85e1cf42a1a3eb8023
noarch tomcat9-webapps-9.0.87-5.el10_0.3.noarch.rpm b98e648515cc9f01ab70110b9341603ebd8309b19ad6cccc3666f1cb98a7c2e1
noarch tomcat9-servlet-4.0-api-9.0.87-5.el10_0.3.noarch.rpm ba8d3466ff4ad274e3084accb553ee8b02a682e2d7af66333708c2e0e84de420
noarch tomcat9-9.0.87-5.el10_0.3.noarch.rpm e680cc721a750fbd0b6b99bbc96fd817d1d52a9aa3f370c4bdeb4c5f7c5e0f27
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.