High severity7.5NVD Advisory· Published Aug 13, 2025· Updated May 12, 2026
CVE-2025-48989
CVE-2025-48989
Description
Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected.
Users are recommended to upgrade to one of versions 11.0.10, 10.1.44 or 9.0.108 which fix the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.apache.tomcat:tomcat-coyoteMaven | >= 11.0.0-M1, < 11.0.10 | 11.0.10 |
org.apache.tomcat:tomcat-coyoteMaven | >= 10.1.0-M1, < 10.1.44 | 10.1.44 |
org.apache.tomcat:tomcat-coyoteMaven | >= 9.0.0.M1, < 9.0.108 | 9.0.108 |
org.apache.tomcat.embed:tomcat-embed-coreMaven | >= 11.0.0-M1, < 11.0.10 | 11.0.10 |
org.apache.tomcat.embed:tomcat-embed-coreMaven | >= 10.1.0-M1, < 10.1.44 | 10.1.44 |
org.apache.tomcat.embed:tomcat-embed-coreMaven | >= 9.0.0.M1, < 9.0.108 | 9.0.108 |
Affected products
79cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*+ 27 more
- cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*range: >=9.0.1,<9.0.108
- cpe:2.3:a:apache:tomcat:9.0.0:milestone1:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone10:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone11:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone12:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone13:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone14:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone15:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone16:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone17:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone18:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone19:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone2:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone20:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone21:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone22:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone23:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone24:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone25:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone26:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone27:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone3:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone4:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone5:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone6:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone7:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone8:*:*:*:*:*:*
- cpe:2.3:a:apache:tomcat:9.0.0:milestone9:*:*:*:*:*:*
- osv-coords50 versionspkg:bitnami/tomcatpkg:maven/org.apache.tomcat.embed/tomcat-embed-corepkg:maven/org.apache.tomcat/tomcat-coyotepkg:rpm/almalinux/tomcatpkg:rpm/almalinux/tomcat9pkg:rpm/almalinux/tomcat9-admin-webappspkg:rpm/almalinux/tomcat9-docs-webapppkg:rpm/almalinux/tomcat9-el-3.0-apipkg:rpm/almalinux/tomcat9-jsp-2.3-apipkg:rpm/almalinux/tomcat9-libpkg:rpm/almalinux/tomcat9-servlet-4.0-apipkg:rpm/almalinux/tomcat9-webappspkg:rpm/almalinux/tomcat-admin-webappspkg:rpm/almalinux/tomcat-docs-webapppkg:rpm/almalinux/tomcat-el-3.0-apipkg:rpm/almalinux/tomcat-jsp-2.3-apipkg:rpm/almalinux/tomcat-libpkg:rpm/almalinux/tomcat-servlet-4.0-apipkg:rpm/almalinux/tomcat-webappspkg:rpm/opensuse/tomcat10&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/tomcat10&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/tomcat11&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/tomcat11&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/tomcat&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/tomcat&distro=openSUSE%20Tumbleweedpkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOSpkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSSpkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP6pkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP7pkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSSpkg:rpm/suse/tomcat10&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5pkg:rpm/suse/tomcat11&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP6pkg:rpm/suse/tomcat11&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP7pkg:rpm/suse/tomcat&distro=SUSE%20Enterprise%20Storage%207.1pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP3-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-ESPOSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP4-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-ESPOSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP5-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP6pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Web%20and%20Scripting%2015%20SP7pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP3-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP4-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP5-LTSSpkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP3pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP4pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP5pkg:rpm/suse/tomcat&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/tomcat&distro=SUSE%20Manager%20Server%20LTS%204.3
< 9.0.108+ 49 more
- (no CPE)range: < 9.0.108
- (no CPE)range: >= 11.0.0-M1, < 11.0.10
- (no CPE)range: >= 11.0.0-M1, < 11.0.10
- (no CPE)range: < 1:9.0.87-1.el8_10.6
- (no CPE)range: < 1:9.0.87-5.el10_0.3
- (no CPE)range: < 1:9.0.87-5.el10_0.3
- (no CPE)range: < 1:9.0.87-5.el10_0.3
- (no CPE)range: < 1:9.0.87-5.el10_0.3
- (no CPE)range: < 1:9.0.87-5.el10_0.3
- (no CPE)range: < 1:9.0.87-5.el10_0.3
- (no CPE)range: < 1:9.0.87-5.el10_0.3
- (no CPE)range: < 1:9.0.87-5.el10_0.3
- (no CPE)range: < 1:9.0.87-1.el8_10.6
- (no CPE)range: < 1:9.0.87-1.el8_10.6
- (no CPE)range: < 1:9.0.87-1.el8_10.6
- (no CPE)range: < 1:9.0.87-1.el8_10.6
- (no CPE)range: < 1:9.0.87-1.el8_10.6
- (no CPE)range: < 1:9.0.87-1.el8_10.6
- (no CPE)range: < 1:9.0.87-1.el8_10.6
- (no CPE)range: < 10.1.44-150200.5.51.1
- (no CPE)range: < 10.1.44-1.1
- (no CPE)range: < 11.0.10-150600.13.9.1
- (no CPE)range: < 11.0.10-1.1
- (no CPE)range: < 9.0.108-150200.91.1
- (no CPE)range: < 9.0.108-1.1
- (no CPE)range: < 10.1.44-150200.5.51.1
- (no CPE)range: < 10.1.44-150200.5.51.1
- (no CPE)range: < 10.1.44-150200.5.51.1
- (no CPE)range: < 10.1.44-150200.5.51.1
- (no CPE)range: < 10.1.44-150200.5.51.1
- (no CPE)range: < 10.1.44-150200.5.51.1
- (no CPE)range: < 11.0.10-150600.13.9.1
- (no CPE)range: < 11.0.10-150600.13.9.1
- (no CPE)range: < 9.0.108-150200.91.1
- (no CPE)range: < 9.0.108-150200.91.1
- (no CPE)range: < 9.0.108-150200.91.1
- (no CPE)range: < 9.0.108-150200.91.1
- (no CPE)range: < 9.0.108-150200.91.1
- (no CPE)range: < 9.0.108-150200.91.1
- (no CPE)range: < 9.0.108-150200.91.1
- (no CPE)range: < 9.0.108-150200.91.1
- (no CPE)range: < 9.0.115-3.160.1
- (no CPE)range: < 9.0.108-150200.91.1
- (no CPE)range: < 9.0.108-150200.91.1
- (no CPE)range: < 9.0.108-150200.91.1
- (no CPE)range: < 9.0.108-150200.91.1
- (no CPE)range: < 9.0.108-150200.91.1
- (no CPE)range: < 9.0.108-150200.91.1
- (no CPE)range: < 9.0.115-3.160.1
- (no CPE)range: < 9.0.108-150200.91.1
- Apache Software Foundation/Apache Tomcatv5Range: 11.0.0-M1
Patches
Vulnerability mechanics
References
12- github.com/advisories/GHSA-gqp3-2cvr-x8m3ghsaADVISORY
- lists.apache.org/thread/9ydfg0xr0tchmglcprhxgwhj0hfwxlyfnvdMailing ListVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2025-48989ghsaADVISORY
- www.openwall.com/lists/oss-security/2025/08/13/2nvdWEB
- cert-portal.siemens.com/productcert/html/ssa-032379.htmlnvdWEB
- github.com/apache/tomcat/commit/73c04a10395774bda71a0b37802cf983662ce255ghsaWEB
- github.com/apache/tomcat/commit/f362c8eb3b8ec5b7f312f7f5610731c0fb299a06ghsaWEB
- github.com/apache/tomcat/commit/f36b8a4eea4ce8a0bc035079e1d259d29f5eb7bfghsaWEB
- tomcat.apache.org/security-10.htmlghsaWEB
- tomcat.apache.org/security-11.htmlghsaWEB
- tomcat.apache.org/security-9.htmlghsaWEB
- www.kb.cert.org/vuls/id/767506nvdWEB
News mentions
1- Siemens SIMATICCISA ICS Advisories