Apache Tomcat: DoS via integer overflow in multipart file upload (CVE-2025-52520)
An integer overflow vulnerability in Apache Tomcat multipart file upload handling can lead to denial of service (DoS) by bypassing size limits under certain unlikely configurations. This affects multiple versions of Apache Tomcat, including 11.0.0 through 11.0.8, 10.1.0 through 10.1.42, 9.0.0 through 9.0.106, and some older EOL versions such as 8.5.0 through 8.5.100. Users are advised to upgrade to fixed versions 11.0.9, 10.1.43, or 9.0.107 to remediate the issue.
AI Analysis
Technical Summary
CVE-2025-52520 describes an integer overflow vulnerability in Apache Tomcat's multipart file upload processing. Under certain unlikely multipart upload configurations, this overflow can bypass configured size limits, resulting in a denial of service condition. The vulnerability affects Apache Tomcat versions from 11.0.0 through 11.0.8, 10.1.0 through 10.1.42, 9.0.0 through 9.0.106, and older EOL versions including 8.5.0 through 8.5.100. The issue is resolved in Apache Tomcat versions 11.0.9, 10.1.43, and 9.0.107, which include fixes to prevent the integer overflow and enforce size limits properly.
Potential Impact
Successful exploitation of this vulnerability can cause a denial of service by bypassing multipart upload size limits, potentially leading to resource exhaustion or application instability. There is no indication of code execution or data breach from the provided information.
Mitigation Recommendations
A patch is available. Users should upgrade Apache Tomcat to versions 11.0.9, 10.1.43, or 9.0.107 or later to remediate this vulnerability. No other mitigation steps are indicated or required.
Apache Tomcat: DoS via integer overflow in multipart file upload (CVE-2025-52520)
Description
An integer overflow vulnerability in Apache Tomcat multipart file upload handling can lead to denial of service (DoS) by bypassing size limits under certain unlikely configurations. This affects multiple versions of Apache Tomcat, including 11.0.0 through 11.0.8, 10.1.0 through 10.1.42, 9.0.0 through 9.0.106, and some older EOL versions such as 8.5.0 through 8.5.100. Users are advised to upgrade to fixed versions 11.0.9, 10.1.43, or 9.0.107 to remediate the issue.
Affected software
pkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps-legacy/xenialpkg:deb/ubuntu/[email protected]~18.04.3+esm6?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm8?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/[email protected]~esm4?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-52520 describes an integer overflow vulnerability in Apache Tomcat's multipart file upload processing. Under certain unlikely multipart upload configurations, this overflow can bypass configured size limits, resulting in a denial of service condition. The vulnerability affects Apache Tomcat versions from 11.0.0 through 11.0.8, 10.1.0 through 10.1.42, 9.0.0 through 9.0.106, and older EOL versions including 8.5.0 through 8.5.100. The issue is resolved in Apache Tomcat versions 11.0.9, 10.1.43, and 9.0.107, which include fixes to prevent the integer overflow and enforce size limits properly.
Potential Impact
Successful exploitation of this vulnerability can cause a denial of service by bypassing multipart upload size limits, potentially leading to resource exhaustion or application instability. There is no indication of code execution or data breach from the provided information.
Mitigation Recommendations
A patch is available. Users should upgrade Apache Tomcat to versions 11.0.9, 10.1.43, or 9.0.107 or later to remediate this vulnerability. No other mitigation steps are indicated or required.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2025-52520
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6a58b50368715ace43db2894
Added to database: 07/16/2026, 10:40:03 UTC
Last enriched: 09/08/2026, 15:06:59 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 27
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.