CVE-2025-61795

medium
Published 2025-10-27 Β· Modified 2026-05-13
CVSS v3
5.3
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
5.3

Description

Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memory usage and application load, it was possible that space for the temporary copies of uploaded parts would be filled faster than GC cleared it, leading to a DoS. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.11, from 10.1.0-M1 through 10.1.46, from 9.0.0.M1 through 9.0.109. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.12 or later, 10.1.47 or later or 9.0.110 or later which fixes the issue.

Predictions

Exploit likelihood
63%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker Β· View original β†— Β· DFSG

CVE-2025-61795 NameCVE-2025-61795 DescriptionImproper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memory…

CVE-2025-61795

NameCVE-2025-61795
DescriptionImproper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memory usage and application load, it was possible that space for the temporary copies of uploaded parts would be filled faster than GC cleared it, leading to a DoS. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.11, from 10.1.0-M1 through 10.1.46, from 9.0.0.M1 through 9.0.109. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.12 or later, 10.1.47 or later or 9.0.110 or later which fixes the issue.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-4468-1, DSA-6120-1, DSA-6121-1
Debian Bugs1119293, 1119294

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tomcat10 (PTS)bookworm, bookworm (security)10.1.52-1~deb12u1fixed
trixie (security), trixie10.1.52-1~deb13u1fixed
forky10.1.54-1fixed
sid10.1.55-1fixed
tomcat11 (PTS)trixie (security), trixie11.0.15-1~deb13u1fixed
forky11.0.21-1fixed
sid11.0.22-2fixed
tomcat9 (PTS)bullseye9.0.43-2~deb11u10vulnerable
bullseye (security)9.0.107-0+deb11u2fixed
bookworm9.0.70-2fixed
trixie9.0.95-1fixed
forky, sid9.0.118-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tomcat10sourcebookworm10.1.52-1~deb12u1DSA-6120-1
tomcat10sourcetrixie10.1.52-1~deb13u1DSA-6120-1
tomcat10source(unstable)10.1.52-11119294
tomcat11sourcetrixie11.0.15-1~deb13u1DSA-6121-1
tomcat11source(unstable)11.0.15-11119293
tomcat9sourcebullseye9.0.107-0+deb11u2DLA-4468-1
tomcat9source(unstable)9.0.70-2

Notes

Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
https://github.com/apache/tomcat/commit/1cdf5f730ede75a0759492f179ac21ca4ff68e06 (11.0.12)
https://github.com/apache/tomcat/commit/af6e9181620304c0d818121c29c074e1330610d0 (10.1.47)
https://github.com/apache/tomcat/commit/afa422bd7ca1eef0f507259c682fd876494d9c3b (9.0.110)
https://lists.apache.org/thread/wm9mx8brmx9g4zpywm06ryrtvd3160pp

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed versionhttps://github.com/apache/tomcat/commit/1cdf5f730ede75a0759492f179ac21ca4ff68e06 (11.0.12)https://github.com/apache/tomcat/commit/af6e9181620304c0d818121c29c074e1330610d0 (10.1.47)https://github.com/apache/tomcat/commit/afa422bd7ca1eef0f507259c682fd876494d9c3b (9.0.110)https://lists.apache.org/thread/wm9mx8brmx9g4zpywm06ryrtvd3160pp

OS impact

suse SUSE Affected 1 release
VersionStatusFixed in
β€” Affected β€”
debian Debian Fixed 5 releases
VersionStatusFixed in
trixie Fixed 10.1.52-1~deb13u1
sid Fixed 10.1.52-1
forky Fixed 10.1.52-1
bullseye Fixed 9.0.107-0+deb11u2
bookworm Fixed 10.1.52-1~deb12u1

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.apache.tomcat:tomcat>=11.0.0-M1,<11.0.1211.0.12
java Mavenorg.apache.tomcat:tomcat>=10.1.0-M1,<10.1.4710.1.47
java Mavenorg.apache.tomcat:tomcat>=9.0.0.M1,<9.0.1109.0.110
java Mavenorg.apache.tomcat:tomcat>=8.5.0,<=8.5.100
java Mavenorg.apache.tomcat:tomcat-catalina>=11.0.0-M1,<11.0.1211.0.12
java Mavenorg.apache.tomcat:tomcat-catalina>=10.1.0-M1,<10.1.4710.1.47
java Mavenorg.apache.tomcat:tomcat-catalina>=9.0.0.M1,<9.0.1109.0.110
java Mavenorg.apache.tomcat:tomcat-catalina>=8.5.0,<=8.5.100
java Mavenorg.apache.tomcat.embed:tomcat-embed-core>=11.0.0-M1,<11.0.1211.0.12
java Mavenorg.apache.tomcat.embed:tomcat-embed-core>=10.1.0-M1,<10.1.4710.1.47
java Mavenorg.apache.tomcat.embed:tomcat-embed-core>=9.0.0.M1,<9.0.1109.0.110
java Mavenorg.apache.tomcat.embed:tomcat-embed-core>=8.5.0,<=8.5.100
java MAVENorg.apache.tomcat.embed:tomcat-embed-core>= 8.5.0, <= 8.5.100
java MAVENorg.apache.tomcat.embed:tomcat-embed-core>= 9.0.0.M1, < 9.0.1109.0.110
java MAVENorg.apache.tomcat:tomcat-catalina>= 8.5.0, <= 8.5.100
java MAVENorg.apache.tomcat:tomcat-catalina>= 9.0.0.M1, < 9.0.1109.0.110
java MAVENorg.apache.tomcat:tomcat>= 8.5.0, <= 8.5.100
java MAVENorg.apache.tomcat:tomcat>= 9.0.0.M1, < 9.0.1109.0.110
java MAVENorg.apache.tomcat.embed:tomcat-embed-core>= 10.1.0-M1, < 10.1.4710.1.47
java MAVENorg.apache.tomcat.embed:tomcat-embed-core>= 11.0.0-M1, < 11.0.1211.0.12
java MAVENorg.apache.tomcat:tomcat-catalina>= 10.1.0-M1, < 10.1.4710.1.47
java MAVENorg.apache.tomcat:tomcat-catalina>= 11.0.0-M1, < 11.0.1211.0.12
java MAVENorg.apache.tomcat:tomcat>= 10.1.0-M1, < 10.1.4710.1.47
java MAVENorg.apache.tomcat:tomcat>= 11.0.0-M1, < 11.0.1211.0.12

Application impact

VendorProductVersionsFixed
apache apachetomcat{"startIncluding":"8.5.0","endIncluding":"8.5.100"}

References

CWEs

CWE-404

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.