CVE-2025-48989 | Apache Tomcat up to 8.5.100/9.0.107/10.1.43/11.0.9 HTTP/2 denial of service (EUVD-2025-24559)
A vulnerability has been found in Apache Tomcat up to 8.5.100/9.0.107/10.1.43/11.0.9 and classified as problematic. Affected by this vulnerability is an unknown functionality of the component HTTP2 Handler. The manipulation leads to denial of service. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is known as CVE-2025-48989. The attack can be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More