Junglewise Threat Intelligence

CVE-2025-52434: Apache Tomcat race condition in APR/Native connector

CVE-2025-52434 · Severity: high · CVSS 7.5 · Published 2025-07-10

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat is a widely used web server for hosting Java applications. A flaw in how it handles specific network connections can allow an attacker to exhaust the server's resources, potentially causing the website or application to become unavailable to legitimate users. This issue is most prominent when the server is configured to use the APR/Native connector and handles HTTP/2 traffic.

Technical details

A race condition exists in Apache Tomcat's APR/Native connector due to improper synchronization when handling shared resources. The vulnerability is triggered during the concurrent execution of connection tasks, specifically when a client initiates the closure of an HTTP/2 connection. An unauthenticated remote attacker can exploit this to cause resource exhaustion, leading to a denial-of-service (DoS) condition. The issue affects Tomcat versions 9.0.0.M1 through 9.0.106 and 8.5.0 through 8.5.100. Users are advised to upgrade to version 9.0.107 or later.

Affected products

  • Apache Tomcat 9.0.0.M1 through 9.0.106, 8.5.0 through 8.5.100

Timeline

  • 2025-07-10: disclosed
  • 2025-07-10: advisory

References

Related threats