Alerts This Week
Warning Icon 1 525
Alerts This Week
Warning Icon 1 525

Debian DSA-6121-1 Tomcat11 Important Denial of Service Vulnerabilities

debian
Calendar Grey February 5, 2026
Debian Logo
Tomcat 11 update resolves several critical flaws enhancing HTTP/2 and preventing denial of service.
Several security vulnerabilities have been found in Tomcat 11, a Java web server and servlet engine

Summary

Several security vulnerabilities have been found in Tomcat 11, a Java web
server and servlet engine. This update improves the handling of HTTP/2
connections and corrects various flaws which can lead to uncontrolled resource
consumption and a denial of service.

For the stable distribution (trixie), these problems have been fixed in
version 11.0.15-1~deb13u1.

We recommend that you upgrade your tomcat11 packages.

For the detailed security status of tomcat11 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/source-package/tomcat11

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/



Severity
important
Lowest
Low
Medium
High
Critical

Package: tomcat11
CVE ID: CVE-2025-46701 CVE-2025-48976 CVE-2025-48988 CVE-2025-48989

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here