CVE-2025-48988
Apache Tomcat: FileUpload large number of parts with headers DoS
Description
Apache Tomcat - DoS in multipart upload
In plain language
AI Worth attentionApache Tomcat can be overwhelmed by a specially crafted file upload; small businesses using it should update promptly.
Unauthenticated network DoS in Apache Tomcat multipart upload processing, where requests containing many parts with headers can exhaust server resources.
What to do now
- Check whether your servers or application dependencies use Apache Tomcat, including embedded Tomcat.
- Upgrade the Tomcat branch you use to 11.0.8, 10.1.42, or 9.0.106.
- If you cannot upgrade promptly, restrict untrusted access to file-upload functions and ask your vendor for its remediation timeline.
- Watch for unusual spikes in multipart upload requests or server resource use after deploying the update.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:NConfidentialityI:NIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2025-48988 and every CVE in our database. Create a free account — no credit card required.
Create Free Account