Back to Vulnerability Directory
HIGHFixed upstream

CVE-2025-48989

Apache Tomcat: HTTP/2 denial of service through client-triggered stream resets (MadeYouReset)

Technology

Apache Tomcat

CVSS Score

7.5 / 10.0

Affected Versions

11.0.0-M1 to 11.0.9; 10.1.0-M1 to 10.1.43; 9.0.0.M1 to 9.0.107; older end-of-life versions may also be affected

Upstream Fix

11.0.10; 10.1.44; 9.0.108

Published

August 13, 2025

OSSeva Coverage

Fixed upstream

Description

Tomcat's HTTP/2 implementation was vulnerable to the "made you reset" attack, in which a client provokes the server into resetting streams. The denial of service typically showed as an OutOfMemoryError. Rated Important by the Tomcat security team. Fixed in 11.0.10, 10.1.44 and 9.0.108.

Upstream record: NVD · CVE.org

Is your Apache Tomcat deployment affected?

If you're running 11.0.0-M1 to 11.0.9; 10.1.0-M1 to 10.1.43; 9.0.0.M1 to 9.0.107; older end-of-life versions may also be affected, you need this patch. Book a discovery call to get covered.