FlawAtlas
Search the atlas
SUSE-SU-2026:1058-1 Not scored

Security update for tomcat

This update for tomcat fixes the following issues: Update to Tomcat 9.0.115: - CVE-2025-48989: HTTP/2 protocol (including DNS over HTTPS) is vulnerable to 'MadeYouReset' DoS attack (bsc#1243895). - CVE-2025-52434: race condition on connection close when using the APR/Native connector could lead to a JVM crash (bsc#1246389). - CVE-2025-53506: uncontrolled resource HTTP/2 client consumption vulnerability (bsc#1246318). - CVE-2025-66614: client certificate verification bypass due to virtual host mapping (bsc#1258371). - CVE-2026-24733: improper input validation on HTTP/0.9 requests (bsc#1258385). - CVE-2023-44487: Rapid reset attack (bsc#1216182).

Exploit probability Not scored
Published March 26, 2026
Required by Not available
Last source change March 27, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Server 12 SP5-LTSS tomcat
SUSE:Linux Enterprise Server LTSS Extended Security 12 SP5 tomcat

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2026:1058-1

This update for tomcat fixes the following issues: Update to Tomcat 9.0.115: - CVE-2025-48989: HTTP/2 protocol (including DNS over HTTPS) is vulnerable to 'MadeYouReset' DoS attack (bsc#1243895). - CVE-2025-52434: race condition on connection close when using the APR/Native connector could lead to a JVM crash (bsc#1246389). - CVE-2025-53506: uncontrolled resource HTTP/2 client consumption vulnerability (bsc#1246318). - CVE-2025-66614: client certificate verification bypass due to virtual host mapping (bsc#1258371). - CVE-2026-24733: improper input validation on HTTP/0.9 requests (bsc#1258385). - CVE-2023-44487: Rapid reset attack (bsc#1216182).

View original source

05 / REFERENCES

Further evidence