ELA-1777-1 tomcat8 security update

denial of service

2026-07-21
Packagetomcat8
Version8.5.54-0+deb9u19 (stretch)
Related CVEs CVE-2025-48976 CVE-2025-48988 CVE-2025-48989 CVE-2025-49125 CVE-2025-52520 CVE-2025-53506 CVE-2025-55668


Several security vulnerabilities were found in Tomcat 8, a Java web server, servlet and JSP engine. A remote attacker may use those flaws to cause a denial of service by allocating system resources with insufficient limits or by circumventing security constraints.



For Debian 9 stretch, these problems have been fixed in version 8.5.54-0+deb9u19.

We recommend that you upgrade your tomcat8 packages.

Further information about Extended LTS security advisories can be found in the dedicated section of our website.