CVE-2025-48989
Apache Tomcat: HTTP/2 denial of service through client-triggered stream resets (MadeYouReset)
Technology
Apache Tomcat
CVSS Score
7.5 / 10.0
Affected Versions
11.0.0-M1 to 11.0.9; 10.1.0-M1 to 10.1.43; 9.0.0.M1 to 9.0.107; older end-of-life versions may also be affected
Upstream Fix
11.0.10; 10.1.44; 9.0.108
Published
August 13, 2025
OSSeva Coverage
Fixed upstream
Description
Tomcat's HTTP/2 implementation was vulnerable to the "made you reset" attack, in which a client provokes the server into resetting streams. The denial of service typically showed as an OutOfMemoryError. Rated Important by the Tomcat security team. Fixed in 11.0.10, 10.1.44 and 9.0.108.
Is your Apache Tomcat deployment affected?
If you're running 11.0.0-M1 to 11.0.9; 10.1.0-M1 to 10.1.43; 9.0.0.M1 to 9.0.107; older end-of-life versions may also be affected, you need this patch. Book a discovery call to get covered.