Apache Tomcat July Vulnerability Security Update Advisory

Apache Tomcat July Vulnerability Security Update Advisory

Overview

 

Apache Tomcat(https://tomcat.apache.org/) has released a security update that addresses a vulnerability in its shipped products. Users of affected products are advised to update to the latest version.

 

Affected Products

 

Apache Tomcat 9.0.0.M1 – 9.0.106

 

Resolved Vulnerabilities

 

Denial of Service Attack Vulnerability in Apache Tomcat (CVE-2025-52520)

Denial of Service Attack Vulnerability in Apache Tomcat (CVE-2025-52434)

Denial of Service Attack Vulnerability in Apache Tomcat (CVE-2025-53506)

 

Vulnerability Patches

 

Please follow the security advisory published on July 4, 2025 to update to the applicable version and the latest version.

Apache Tomcat 9.0.107

 

Referenced Sites

 

[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-52434

[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-52520

[3] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-53506

[4] https://tomcat.apache.org/security