Apache Tomcat: Delayed cleaning of multi-part upload temporary files may lead to DoS (CVE-2025-61795)
Apache Tomcat versions from 9.0.0 through 9.0.109, 10.1.0 through 10.1.46, and 11.0.0 through 11.0.11 have a vulnerability where temporary files from multipart uploads are not immediately cleaned up if an error occurs. This delayed cleanup can cause disk space exhaustion leading to denial of service (DoS). The issue affects some older EOL versions as well. Fixed versions are 9.0.110 or later, 10.1.47 or later, and 11.0.12 or later.
AI Analysis
Technical Summary
CVE-2025-61795 is an Improper Resource Shutdown or Release vulnerability in Apache Tomcat. When processing multipart uploads, if an error occurs (including exceeding limits), temporary copies of uploaded parts written to disk are not cleaned up immediately but rely on garbage collection to delete them. Depending on JVM settings, application memory usage, and load, this can cause disk space to fill faster than garbage collection can clear it, resulting in a denial of service. Affected versions include Apache Tomcat 11.0.0 through 11.0.11, 10.1.0 through 10.1.46, and 9.0.0 through 9.0.109, as well as some older EOL versions like 8.5.0 through 8.5.100. The issue is fixed in versions 11.0.12, 10.1.47, and 9.0.110 and later.
Potential Impact
The vulnerability can lead to denial of service by exhausting disk space due to delayed cleanup of temporary multipart upload files. This can degrade or disrupt the availability of Apache Tomcat services until disk space is freed or the server is restarted.
Mitigation Recommendations
A fix is available. Users should upgrade to Apache Tomcat versions 11.0.12 or later, 10.1.47 or later, or 9.0.110 or later to resolve this issue. No other mitigation actions are specifically recommended by the vendor advisory.
Apache Tomcat: Delayed cleaning of multi-part upload temporary files may lead to DoS (CVE-2025-61795)
Description
Apache Tomcat versions from 9.0.0 through 9.0.109, 10.1.0 through 10.1.46, and 11.0.0 through 11.0.11 have a vulnerability where temporary files from multipart uploads are not immediately cleaned up if an error occurs. This delayed cleanup can cause disk space exhaustion leading to denial of service (DoS). The issue affects some older EOL versions as well. Fixed versions are 9.0.110 or later, 10.1.47 or later, and 11.0.12 or later.
Affected software
pkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra-legacy/trustypkg:deb/ubuntu/[email protected]+esm2?arch=source&distro=esm-infra-legacy/xenialpkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps-legacy/xenialpkg:deb/ubuntu/[email protected]~18.04.3+esm6?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm8?arch=source&distro=esm-apps/bionicpkg:deb/ubuntu/[email protected]+esm3?arch=source&distro=esm-apps/focalpkg:deb/ubuntu/[email protected]+esm4?arch=source&distro=esm-apps/jammypkg:deb/ubuntu/[email protected]~esm4?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]?arch=source&distro=questingpkg:deb/ubuntu/[email protected]~26.04.1?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2025-61795 is an Improper Resource Shutdown or Release vulnerability in Apache Tomcat. When processing multipart uploads, if an error occurs (including exceeding limits), temporary copies of uploaded parts written to disk are not cleaned up immediately but rely on garbage collection to delete them. Depending on JVM settings, application memory usage, and load, this can cause disk space to fill faster than garbage collection can clear it, resulting in a denial of service. Affected versions include Apache Tomcat 11.0.0 through 11.0.11, 10.1.0 through 10.1.46, and 9.0.0 through 9.0.109, as well as some older EOL versions like 8.5.0 through 8.5.100. The issue is fixed in versions 11.0.12, 10.1.47, and 9.0.110 and later.
Potential Impact
The vulnerability can lead to denial of service by exhausting disk space due to delayed cleanup of temporary multipart upload files. This can degrade or disrupt the availability of Apache Tomcat services until disk space is freed or the server is restarted.
Mitigation Recommendations
A fix is available. Users should upgrade to Apache Tomcat versions 11.0.12 or later, 10.1.47 or later, or 9.0.110 or later to resolve this issue. No other mitigation actions are specifically recommended by the vendor advisory.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2025-61795
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:Pro:14.04:LTS","Ubuntu:Pro:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:Pro:22.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
- Cvss Version
- 3.1
Threat ID: 6a58b50368715ace43db2874
Added to database: 07/16/2026, 10:40:03 UTC
Last enriched: 09/08/2026, 15:06:12 UTC
Last updated: 09/10/2026, 20:52:22 UTC
Views: 31
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.