Skip to main content

Improper Resource Shutdown or Release

CVE-2025-48989

Severity High
Score 7.5/10

Summary

Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat versions 8.5.0 through 9.0.107, 10.0.0-M1 through 10.1.43, and 11.0.0-M1 through 11.0.9. Older, EOL versions may also be affected.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-404 - Improper Resource Shutdown or Release

The program does not release or incorrectly releases a resource before it is made available for re-use.

Advisory Timeline

  • Published