Threats Tagged 'cve-2025-52434'
View all threats tagged with 'cve-2025-52434'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve-2025-52434'
Click on any threat for detailed analysis and mitigation recommendations
A race condition vulnerability in Apache Tomcat's APR/Native connector can cause the server to crash, leading to a denial of service (DoS). This issue occurs when client-initiated closes of HTTP/2 connections happen concurrently, affecting Apache Tomcat versions from 8.5.0 through 8.5.100 and 9.0.0 through 9.0.106. The vulnerability has been fixed in version 9.0.107. Users are advised to upgrade to this version to mitigate the issue. Join the discussion | GCVE Database | 05/18/2026, 08:57:54 UTC Added: 07/16/2026, 10:40:07 UTC |
0 Multiple security vulnerabilities affecting Apache Tomcat and Apache Commons FileUpload components in Red Hat Enterprise Linux 9.4 Extended Update Support have been addressed. These include denial of service (DoS) issues in multipart upload handling, HTTP/2 control frames, and part headers, as well as a security constraint bypass vulnerability. Red Hat has released an important security update to remediate these issues. Join the discussion | GCVE Database | 08/20/2025, 15:43:40 UTC Added: 06/28/2026, 22:14:14 UTC |
0 Multiple security vulnerabilities affecting Apache Tomcat and Apache Commons FileUpload have been addressed in a Red Hat Enterprise Linux 9 update. These include denial of service (DoS) issues in multipart upload handling, HTTP/2 control frames, and part headers, as well as a security constraint bypass vulnerability. The update is rated as important by Red Hat Product Security and affects various Red Hat Enterprise Linux 9 variants and architectures. No CVSS scores are provided in the advisory, but the severity is assessed as high. Users of affected Red Hat Enterprise Linux 9 packages should apply the provided security update to mitigate these vulnerabilities. Join the discussion | GCVE Database | 08/20/2025, 15:41:15 UTC Added: 06/28/2026, 22:14:14 UTC |
0 Multiple security vulnerabilities affecting Apache Tomcat and Apache Commons FileUpload components in Red Hat Enterprise Linux 8 have been addressed in an important security update. These include denial of service (DoS) issues via multipart upload, HTTP/2 control frames, and part headers, as well as a security constraint bypass vulnerability. The update fixes seven CVEs related to these issues. Red Hat has released patches for affected versions to mitigate these vulnerabilities. Join the discussion | GCVE Database | 08/20/2025, 15:37:48 UTC Added: 06/28/2026, 22:14:15 UTC |
0 Red Hat has issued a security advisory for Apache Tomcat addressing multiple denial of service (DoS) vulnerabilities and a security constraint bypass. The vulnerabilities affect multipart upload processing, HTTP/2 control frames, and Apache Commons FileUpload part headers. The advisory covers Red Hat Enterprise Linux 8.8 variants and provides updated Tomcat packages to fix these issues. No CVSS scores are provided, but the vulnerabilities are rated as having a high security impact. No known exploits in the wild have been reported at this time. Join the discussion | GCVE Database | 08/20/2025, 15:36:45 UTC Added: 06/28/2026, 22:14:14 UTC |
0 Multiple denial of service (DoS) vulnerabilities and a security constraint bypass issue have been identified in Apache Tomcat and Apache Commons FileUpload components used in Red Hat Enterprise Linux 9.2 and 10. These vulnerabilities include DoS via multipart upload, HTTP/2 control frames, and part headers, as well as a security constraint bypass affecting pre/post-resources. Red Hat has released security updates addressing these issues for affected versions of Tomcat in Red Hat Enterprise Linux 9.2 and 10. Join the discussion | GCVE Database | 08/20/2025, 15:36:15 UTC Added: 06/28/2026, 22:14:14 UTC |
0 Multiple security vulnerabilities affecting Apache Tomcat 9, as packaged in Red Hat Enterprise Linux 10, have been addressed in a security update. These include denial of service (DoS) issues via multipart upload, HTTP/2 control frames, and Apache Commons FileUpload part headers, as well as a security constraint bypass vulnerability. The update fixes seven CVEs related to these issues. Red Hat has released patches for affected versions and recommends applying the update to mitigate these vulnerabilities. Join the discussion | GCVE Database | 08/20/2025, 15:33:55 UTC Added: 06/28/2026, 22:14:15 UTC |
0 Red Hat JBoss Web Server is a fully integrated and certified set of components for hosting Java web applications. It is comprised of the Apache Tomcat Servlet container, JBoss HTTP Connector (mod_cluster), the PicketLink Vault extension for Apache Tomcat, and the Tomcat Native library. This release of Red Hat JBoss Web Server 5.8.5 serves as a replacement for Red Hat JBoss Web Server 5.8.4. This release includes bug fixes, enhancements and component upgrades, which are documented in the Release Notes that are linked to in the References section. Security Fix(es): * tomcat: Apache Tomcat DoS in multipart upload [jws-5] (CVE-2025-48988) * tomcat-catalina: Apache Tomcat: Security constraint bypass for pre/post-resources [jws-5] (CVE-2025-49125) * tomcat: Apache Commons FileUpload DoS via part headers [jws-5] (CVE-2025-48976) * jws5-tomcat: Apache Tomcat denial of service [jws-5] (CVE-2025-52520) * jws5-tomcat: Apache Tomcat denial of service [jws-5] (CVE-2025-52434) * jws5-tomcat: Apache Tomcat denial of service [jws-5] (CVE-2025-53506) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. Join the discussion | GCVE Database | 07/28/2025, 13:56:27 UTC Added: 06/28/2026, 22:14:17 UTC |
0 Red Hat JBoss Web Server 5.8.5 includes multiple security fixes addressing denial of service (DoS) vulnerabilities and a security constraint bypass in Apache Tomcat and Apache Commons FileUpload components. These issues affect Red Hat JBoss Web Server 5.8 on Red Hat Enterprise Linux 7, 8, and 9. The update replaces version 5.8.4 and provides bug fixes, enhancements, and component upgrades. The vulnerabilities have been rated with moderate severity by Red Hat Product Security. Join the discussion | GCVE Database | 07/28/2025, 13:54:01 UTC Added: 06/28/2026, 22:14:17 UTC |
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 9.0.107, which fixes the issue. Join the discussion | CVE Database V5 | 07/10/2025, 19:03:47 UTC Added: 07/10/2025, 19:16:07 UTC |
Showing 1 to 10 of 10 results