CVE-2025-31650
Description
Important: tomcat security update
Predictions
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2025-11335.html
Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2025-11333.html
Vendor advisory: alma — https://bugzilla.redhat.com/2362783
Vendor advisory: alma — https://bugzilla.redhat.com/2333521
Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2025:11333
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2025-31650
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2025:11335
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2025-31650.html
Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2025:11333
Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2025:11335
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| arch | affected | | |
| rhel | 9 | fixed | |
| rocky | 8 | fixed | |
| sles | affected | | |
| rocky | 9 | fixed | |
| debian | bullseye | fixed | 9.0.107-0+deb11u1 |
| debian | bookworm | fixed | 10.1.40-1 |
| debian | forky | fixed | 10.1.40-1 |
| debian | sid | fixed | 10.1.40-1 |
| debian | trixie | fixed | 10.1.40-1 |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | org.apache.tomcat:tomcat-coyote | >=9.0.76,<9.0.104 | 9.0.104 |
| Maven | org.apache.tomcat:tomcat-coyote | >=10.1.10,<10.1.40 | 10.1.40 |
| Maven | org.apache.tomcat:tomcat-coyote | >=11.0.0-M2,<11.0.6 | 11.0.6 |
| Maven | org.apache.tomcat.embed:tomcat-embed-core | >=9.0.76,<9.0.104 | 9.0.104 |
| Maven | org.apache.tomcat.embed:tomcat-embed-core | >=10.1.10,<10.1.40 | 10.1.40 |
| Maven | org.apache.tomcat.embed:tomcat-embed-core | >=11.0.0-M2,<11.0.6 | 11.0.6 |
| Maven | org.apache.tomcat:tomcat-coyote | >=8.5.0,<=8.5.100 | |
| Maven | org.apache.tomcat.embed:tomcat-embed-core | >=8.5.0,<=8.5.100 | |
References
- https://access.redhat.com/errata/RHSA-2025:11335
- https://errata.rockylinux.org/RLSA-2025:11333
- https://nvd.nist.gov/vuln/detail/CVE-2025-31650
- https://github.com/apache/tomcat/commit/1eef1dc459c45f1e421d8bd25ef340fc1cc34edc
- https://github.com/apache/tomcat/commit/40ae788c2e64d018b4e58cd4210bb96434d0100d
- https://github.com/apache/tomcat/commit/75554da2fc5574862510ae6f0d7b3d78937f1d40
- https://github.com/apache/tomcat/commit/8cc3b8fb3f2d8d4d6a757e014f19d1fafa948a60
- https://github.com/apache/tomcat/commit/b7674782679e1514a0d154166b1d04d38aaac4a9
- https://github.com/apache/tomcat/commit/b98e74f517b36929f4208506e5adad22cb767baa
- https://github.com/apache/tomcat/commit/cba1a0fe1289ee7f5dd46c61c38d1e1ac5437bff
- https://github.com/apache/tomcat/commit/ded0285b96b4d3f5560dfc8856ad5ec4a9b50ba9
- https://github.com/apache/tomcat/commit/f619e6a05029538886d5a9d987925d573b5bb8c2
- https://github.com/apache/tomcat
- https://lists.apache.org/thread/j6zzk0y3yym9pzfzkq5vcyxzz0yzh826
- https://lists.debian.org/debian-lts-announce/2025/07/msg00009.html
- https://tomcat.apache.org/security-10.html
- https://tomcat.apache.org/security-11.html
- https://tomcat.apache.org/security-9.html
- http://www.openwall.com/lists/oss-security/2025/04/28/2
- https://www.suse.com/security/cve/CVE-2025-31650.html
- https://errata.rockylinux.org/RLSA-2025:11335
- https://security-tracker.debian.org/tracker/CVE-2025-31650
- https://access.redhat.com/errata/RHSA-2025:11333
- https://bugzilla.redhat.com/2333521
- https://bugzilla.redhat.com/2362783
Verify integrity in audit chain (admin only). AS-IS.