## This update for tomcat fixes the following issues: Update to Tomcat 9.0.115: * CVE-2025-48989: HTTP/2 protocol (including DNS over HTTPS) is vulnerable to "MadeYouReset" DoS attack (bsc#1243895). * CVE-2025-52434: race condition on connection close when using the APR/Native connector could lead to a JVM crash (bsc#1246389). * CVE-2025-53506: uncontrolled resource HTTP/2 client consumption vulnerability (bsc#1246318). * CVE-2025-66614: client certificate verification bypass due to virtual host mapping (bsc#1258371). * CVE-2026-24733: improper input validation on HTTP/0.9 requests (bsc#1258385). * CVE-2023-44487: Rapid reset attack (bsc#1216182). ## Patch Instructions: To install this SUSE update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
* bsc#1216182
* bsc#1243895
* bsc#1246318
* bsc#1246389
* bsc#1258371
* bsc#1258385
* bsc#1259224
Cross-
* CVE-2020-13934
* CVE-2020-13935
* CVE-2020-13943
* CVE-2020-17527
* CVE-2021-24122
* CVE-2021-25122
* CVE-2021-25329
* CVE-2021-30640
* CVE-2021-33037
* CVE-2021-41079
* CVE-2021-43980
* CVE-2022-23181
* CVE-2022-42252
* CVE-2023-24998
* CVE-2023-28708
* CVE-2023-28709
* CVE-2023-41080
* CVE-2023-42795
* CVE-2023-44487
* CVE-2023-45468
* CVE-2023-46589
* CVE-2024-21733
* CVE-2024-23672
* CVE-2024-24549
* CVE-2024-34750
* CVE-2024-38286
* CVE-2024-50379
* CVE-2024-52316
* CVE-2024-54677
* CVE-2025-24813
* CVE-2025-31651
* CVE-2025-46701
* CVE-2025-48988
* CVE-2025-48989
* CVE-2025-49125
* CVE-2025-52434
* CVE-2025-52520
* CVE-2025-53506
* CVE-2025-55752
* CVE-2025-55754
Get the latest Linux and open source security news straight to your inbox.