CVE-2025-48989: Apache Tomcat: h2 DoS - Made You Reset
HTTP/2 (including DNS over HTTPS) contains a design flaw and is vulnerable to "MadeYouReset" DoS attack through HTTP/2 control frames Vulnerabilities.
Other sources
Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected.
Users are recommended to upgrade to one of versions 11.0.10, 10.1.44 or 9.0.108 which fix the issue.
— GitHub
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-coyoteto a version that resolves this vulnerability.Fixed in 9.0.108 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-coyoteto a version that resolves this vulnerability.Fixed in 10.1.44 - Upgrade
Upgrade
maven/org.apache.tomcat:tomcat-coyoteto a version that resolves this vulnerability.Fixed in 11.0.10 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 9.0.108 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 10.1.44 - Upgrade
Upgrade
maven/org.apache.tomcat.embed:tomcat-embed-coreto a version that resolves this vulnerability.Fixed in 11.0.10 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.10 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.44 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.108
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48989?
CVE-2025-48989 is categorized with a moderate severity level due to its potential impacts on resource management.
How do I fix CVE-2025-48989?
To remediate CVE-2025-48989, upgrade Apache Tomcat to version 11.0.10 or later, 10.1.44 or later, or 9.0.108 or later.
What versions of Apache Tomcat are affected by CVE-2025-48989?
CVE-2025-48989 affects Apache Tomcat versions 11.0.0-M1 through 11.0.9, 10.1.0-M1 through 10.1.43, and 9.0.0.M1 through 9.0.107.
What is the nature of the vulnerability identified in CVE-2025-48989?
CVE-2025-48989 is an improper resource shutdown or release vulnerability that can lead to the made you reset attack.
Is there a risk of exploitation for CVE-2025-48989?
Yes, CVE-2025-48989 poses a risk of exploitation through denial-of-service attacks if not addressed in affected versions.