#1108119 tomcat10: CVE-2025-48976

Package:
src:tomcat10
Source:
src:tomcat10
Submitter:
Salvatore Bonaccorso
Date:
2025-06-20 19:49:03 UTC
Severity:
normal
Tags:
#1108119#5
Date:
2025-06-20 19:46:42 UTC
From:
To:
Hi,

The following vulnerability was published for tomcat11.

CVE-2025-48976[0]:
| Allocation of resources for multipart headers with insufficient
| limits enabled a DoS vulnerability in Apache Commons FileUpload.
| This issue affects Apache Commons FileUpload: from 1.0 before 1.6;
| from 2.0.0-M1 before 2.0.0-M4.  Users are recommended to upgrade to
| versions 1.6 or 2.0.0-M4, which fix the issue.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-48976
https://www.cve.org/CVERecord?id=CVE-2025-48976

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore