🛡️ SUSE-SU-2025:03006-1 — tomcat10 (CVE-2025-48989)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for tomcat10

This update for tomcat10 fixes the following issues:

Updated to Tomcat 10.1.44:

  • CVE-2025-48989: Fixed 'MadeYouReset' DoS in HTTP/2 due to client triggered stream reset (bsc#1243895)

Other fixes:

  • Catalina

+ Fix: Fix bloom filter population for archive indexing when using a packed

WAR containing one or more JAR files. (markt)

  • Coyote

+ Fix: 69748: Add missing call to set keep-alive timeout when using

HTTP/1.1 following an async request, which was present for AJP.

(remm/markt)

+ Fix: 69762: Fix possible overflow during HPACK decoding of integers. Note

that the maximum permitted value of an HPACK decoded integer is

Integer.MAX_VALUE. (markt)

+ Fix: Update the HTTP/2 overhead documentation - particularly the code

comments - to reflect the deprecation of the PRIORITY frame and clarify

that a stream reset always triggers an overhead increase. (markt)

+ Fix: 69762: Additional overflow fix for HPACK decoding of integers. Pull

request #880 by Chenjp. (markt)

  • Cluster

+ Update: Add enableStatistics configuration attribute for the

DeltaManager, defaulting to true. (remm)

  • WebSocket

+ Fix: Align the WebSocket extension handling for WebSocket client

connections with WebSocket server connections. The WebSocket client now

only includes an extension requested by an endpoint in the opening

handshake if the WebSocket client supports that extension. (markt)

  • Web applications

+ Fix: Manager and Host Manager. Provide the Manager and Host Manager web

applications with a dedicated favicon file rather than using the one from

the ROOT web application which might not be present or may represent

something entirely different. Pull requests #876 and #878 by Simon Arame.

  • Other

+ Update: Update Checkstyle to 10.26.1. (markt)

+ Add: Improvements to French translations. (remm)

+ Add: Improvements to Japanese translations by tak7iji. (markt)

Affected software

SUSE-SU-2025:03006-1 is recorded against 1 package.

  • tomcat10 (fixed in 10.1.44-150200.5.51.1)

Timeline and source

Published on 28 August 2025 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
www.suse.com (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-08-28
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
tomcat10 10.1.44-150200.5.51.1

Free Vulnerability Check

Is your site affected by SUSE-SU-2025:03006-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2025:03006-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSESUSE 2025