{
  "cves": [
    "CVE-2025-48989",
    "CVE-2025-52520",
    "CVE-2025-48988",
    "CVE-2025-52434",
    "CVE-2025-49125",
    "CVE-2025-48976",
    "CVE-2025-53506"
  ],
  "cvss": 0.0,
  "database_specific": {
    "severity": "IMPORTANT"
  },
  "description": "[1:9.0.87-1.el8_10.6]\n- Resolves: RHEL-102193\n  tomcat: http/2 'MadeYouReset' DoS attack through HTTP/2 control frames (CVE-2025-48989)\n\n[1:9.0.87-1.el8_10.5]\n- Resolves: RHEL-108486\n  tomcat: Apache Commons FileUpload DOS via part headers (CVE-2025-48976)\n- Resolves: RHEL-108494\n  tomcat: Dos in multipart upload (CVE-2025-48988)\n- Resolves: RHEL-108502\n  tomcat: Security constraint bypass for pre/post-resources (CVE-2025-49125)\n- Resolves: RHEL-108510\n  tomcat: Denial of service (CVE-2025-52434)\n- Resolves: RHEL-108524\n  tomcat: Denial of service (CVE-2025-52520)\n- Resolves: RHEL-108518\n  tomcat: Denial of service (CVE-2025-53506)",
  "id": "ELSA-2025-14177",
  "ovalId": "oval:com.oracle.elsa:def:202514177",
  "source": "oracle_linux",
  "title": "ELSA-2025-14177:  tomcat security update (IMPORTANT)",
  "url": "https://linux.oracle.com/errata/ELSA-2025-14177.html"
}