CVE-2025-48989 | Apache Tomcat up to 8.5.100/9.0.107/10.1.43/11.0.9 HTTP/2 denial of service (EUVD-2025-24559 / Nessus ID 249345)
A vulnerability categorized as problematic has been discovered in Apache Tomcat up to 8.5.100/9.0.107/10.1.43/11.0.9. The affected element is an unknown function of the component HTTP2 Handler. The manipulation results in denial of service. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability was named CVE-2025-48989. The attack may be performed from remote. There is no available exploit.
It is advisable to upgrade the affected component.