Apache Tomcat July Vulnerability Security Update Advisory
Overview
Apache Tomcat(https://tomcat.apache.org/) has released a security update that addresses a vulnerability in its shipped products. Users of affected products are advised to update to the latest version.
Affected Products
Apache Tomcat 9.0.0.M1 – 9.0.106
Resolved Vulnerabilities
Denial of Service Attack Vulnerability in Apache Tomcat (CVE-2025-52520)
Denial of Service Attack Vulnerability in Apache Tomcat (CVE-2025-52434)
Denial of Service Attack Vulnerability in Apache Tomcat (CVE-2025-53506)
Vulnerability Patches
Please follow the security advisory published on July 4, 2025 to update to the applicable version and the latest version.
Apache Tomcat 9.0.107
Referenced Sites
[1] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-52434
[2] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-52520
[3] http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-53506