CVE-2025-53506: Apache Tomcat: DoS via excessive h...
OSS Security
Jul 10
20:12
Apache Tomcat Coyote Flaw Allows Attackers to Laun...
GB Hackers
Jul 15
09:15
Apache Tomcat Coyote Vulnerability Let Attackers T...
Cybersecurity News
Primary Article
Jul 15
19:05
Primary Article
Cybersecurity News 13 hours ago
A newly disclosed flaw in Apache Tomcat’s Coyote engine—tracked as CVE-2025-53506—has surfaced in the latest round of HTTP/2 security advisories.
First noted in the National Vulnerability Database five days ago, the weakness stems from Coyote’s failure to enforce a hard cap on concurrent streams when an HTTP/2 client never acknowledges the server’s initialSETTINGSframe.
By repeatedly initiating streams that are never closed, aremote attackercan exhaust the server’s thread pool and force the container into a prolonged denial-of-service state, even though confidentiality and integrity remain unaffected.
Because the exploit rides ordinary TCP port 443 traffic, firewalls see nothing suspicious; attack complexity remains low, and no credentials are required.
GitHub analysts subsequentlytracedthe issue to a race condition introduced during the refactor that added dynamic stream limits, publishing proof-of-concept traffic captures that reliably crash unpatched builds.
The vulnerability affect...
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Unlock AI Insights
Get AI-generated executive, technical, and remediation briefs with Pro.
Apache Tomcat Coyote Flaw Allows Attackers to Launch DoS Attacks
The Apache Software Foundation has revealed a vulnerability in the Tomcat Coyote module, specifically within the Maven artifact org.apa...
oss-secmailing list archives
CVE-2025-53506: Apache Tomcat: DoS via excessive h2 streams at connection start
Current thread:
CVE-2025-53506: Apache Tomcat: DoS via excessive h2 streams at connection s...
oss-secmailing list archives
CVE-2025-52434: Apache Tomcat: APR/Native Connector crash leading to DoS
Current thread:
CVE-2025-52434: Apache Tomcat: APR/Native Connector crash leading to DoSMark Thoma...
Save to Folder
Choose a folder to save this cluster:
We use cookies
We use cookies and similar technologies to enhance your experience, analyse site usage, and assist in our marketing efforts.
Cookie Settings
Essential Cookies
Required for the website to function. Cannot be disabled.
Session management and authentication
Security and fraud prevention
Cookie consent preferences
Analytics Cookies
Help us understand how visitors interact with our website.