Improper Resource Shutdown or Release in org.apache.tomcat.embed:tomcat-embed-core
CVE-2025-48989
- org.apache.tomcat.embed:tomcat-embed-core
- org.apache.tomcat.experimental:tomcat-embed-programmatic
- org.apache.tomcat:tomcat-coyote
Summary
Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat versions 8.5.0 through 9.0.107, 10.0.0-M1 through 10.1.43, and 11.0.0-M1 through 11.0.9. Older, EOL versions may also be affected.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- NONE
- HIGH
CWE-404 - Improper Resource Shutdown or Release
The program does not release or incorrectly releases a resource before it is made available for re-use.
Advisory Timeline
- Published