Apache Tomcat: DoS via excessive h2 streams at connection start (CVE-2025-53506)
Apache Tomcat contains an Uncontrolled Resource Consumption vulnerability affecting HTTP/2 clients that do not acknowledge the initial settings frame reducing the maximum concurrent streams. This can lead to a denial of service (DoS) condition. The issue impacts multiple versions across the 8.5.x, 9.0.x, 10.1.x, and 11.0.x branches. Fixed versions are 11.0.9, 10.1.43, and 9.0.107. Users are advised to upgrade to these versions to mitigate the risk.
AI Analysis
Technical Summary
CVE-2025-53506 is an Uncontrolled Resource Consumption vulnerability in Apache Tomcat where an HTTP/2 client that fails to acknowledge the initial settings frame, which reduces the maximum permitted concurrent streams, can cause excessive resource usage leading to denial of service. Affected versions include 8.5.0 through 8.5.100, 9.0.0 through 9.0.106, 10.1.0 through 10.1.42, and 11.0.0 through 11.0.8. The vulnerability is addressed in Apache Tomcat versions 11.0.9, 10.1.43, and 9.0.107.
Potential Impact
Successful exploitation allows an attacker to cause a denial of service by exhausting server resources through excessive HTTP/2 streams at connection start. This can degrade or disrupt service availability for legitimate users.
Mitigation Recommendations
A patch is available and users should upgrade to Apache Tomcat versions 11.0.9, 10.1.43, or 9.0.107 or later to remediate this vulnerability. No additional mitigation steps are indicated by the vendor advisory.
Apache Tomcat: DoS via excessive h2 streams at connection start (CVE-2025-53506)
Description
Apache Tomcat contains an Uncontrolled Resource Consumption vulnerability affecting HTTP/2 clients that do not acknowledge the initial settings frame reducing the maximum concurrent streams. This can lead to a denial of service (DoS) condition. The issue impacts multiple versions across the 8.5.x, 9.0.x, 10.1.x, and 11.0.x branches. Fixed versions are 11.0.9, 10.1.43, and 9.0.107. Users are advised to upgrade to these versions to mitigate the risk.
Affected software
pkg:deb/ubuntu/[email protected]~18.04.3+esm6?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm8?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/[email protected]~esm4?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resolutepkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-53506 is an Uncontrolled Resource Consumption vulnerability in Apache Tomcat where an HTTP/2 client that fails to acknowledge the initial settings frame, which reduces the maximum permitted concurrent streams, can cause excessive resource usage leading to denial of service. Affected versions include 8.5.0 through 8.5.100, 9.0.0 through 9.0.106, 10.1.0 through 10.1.42, and 11.0.0 through 11.0.8. The vulnerability is addressed in Apache Tomcat versions 11.0.9, 10.1.43, and 9.0.107.
Potential Impact
Successful exploitation allows an attacker to cause a denial of service by exhausting server resources through excessive HTTP/2 streams at connection start. This can degrade or disrupt service availability for legitimate users.
Mitigation Recommendations
A patch is available and users should upgrade to Apache Tomcat versions 11.0.9, 10.1.43, or 9.0.107 or later to remediate this vulnerability. No additional mitigation steps are indicated by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2025-53506
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6a58b50368715ace43db288c
Added to database: 07/16/2026, 10:40:03 UTC
Last enriched: 09/08/2026, 15:06:53 UTC
Last updated: 09/10/2026, 19:36:51 UTC
Views: 24
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.