| Package | tomcat8 |
|---|---|
| Version | 8.5.54-0+deb9u19 (stretch) |
| Related CVEs | CVE-2025-48976 CVE-2025-48988 CVE-2025-48989 CVE-2025-49125 CVE-2025-52520 CVE-2025-53506 CVE-2025-55668 |
Several security vulnerabilities were found in Tomcat 8, a Java web server, servlet and JSP engine. A remote attacker may use those flaws to cause a denial of service by allocating system resources with insufficient limits or by circumventing security constraints.
For Debian 9 stretch, these problems have been fixed in version 8.5.54-0+deb9u19.
We recommend that you upgrade your tomcat8 packages.
Further information about Extended LTS security advisories can be found in the dedicated section of our website.