CVE-2025-52434

Published Jul 10, 2025

Last updated 4 months ago

Overview

Description
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 9.0.107, which fixes the issue.
Source
security@apache.org
NVD status
Modified
Products
tomcat

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
HIGH

Weaknesses

security@apache.org
CWE-362

Social media

Hype score
Not currently trending
  1. 🔴 Apache Tomcat, Race Condition Vulnerability, #CVE-2025-52434 (Critical) https://t.co/szPrBlargS

    @dailycve

    29 Jul 2025

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. CVE-2025-52434: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.

    @ZeroDayFacts

    18 Jul 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. CVE-2025-52434 (CVSS:7.5, HIGH) is Received. Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomc..https://t.co/w03baSrIOJ #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    15 Jul 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. ⚠️Vulnerabilidades en Apache Tomcat y HTTP Server ❗CVE-2025-53506 ❗CVE-2025-52434 ❗CVE-2025-52520 ➡️Más info: https://t.co/U9MhlJDNxE https://t.co/nKJdkYnXTS

    @CERTpy

    14 Jul 2025

    135 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2025-52434 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This w… https://t.co/FRsXia7qUu

    @CVEnew

    11 Jul 2025

    264 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. Warning: Multiple vulnerabilities in @TheApacheTomcat can lead to Denial of Service attacks. CVE-2025-52434, CVE-2025-52520, CVE-2025-53506 with CVSS 6.6 demand urgent action. Protect your systems now! Read the advisory https://t.co/I7TVCH9xgC #Patch immediately! #Vulnerability

    @CCBalert

    7 Jul 2025

    90 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    2 Quotes

Configurations