{"cves":["CVE-2025-48988","CVE-2025-49125","CVE-2025-52434","CVE-2025-48976","CVE-2025-52520","CVE-2025-53506","CVE-2025-48989"],"cvss":0.0,"database_specific":{"severity":"IMPORTANT"},"description":"[1:9.0.87-3.el9_6.3]\n- Resolves: RHEL-102200\n  tomcat: http/2 'MadeYouReset' DoS attack through HTTP/2 control frames (CVE-2025-48989)\n\n[1:9.0.87-3.el9_6.2]\n- Resolves: RHEL-108491\n  tomcat: Apache Commons FileUpload DOS via part headers (CVE-2025-48976)\n- Resolves: RHEL-108499\n  tomcat: Dos in multipart upload (CVE-2025-48988)\n- Resolves: RHEL-108507\n  tomcat: Security constraint bypass for pre/post-resources (CVE-2025-49125)\n- Resolves: RHEL-108515\n  tomcat: Denial of service (CVE-2025-52434)\n- Resolves: RHEL-108531\n  tomcat: Denial of service (CVE-2025-52520)\n- Resolves: RHEL-108527\n  tomcat: Denial of service (CVE-2025-53506)","id":"ELSA-2025-14181","ovalId":"oval:com.oracle.elsa:def:202514181","source":"oracle_linux","title":"ELSA-2025-14181:  tomcat security update (IMPORTANT)","url":"https://linux.oracle.com/errata/ELSA-2025-14181.html"}