vulnerability

Apache Tomcat: Low: Delayed cleaning of multipart upload temporary files may lead to DoS (CVE-2025-61795)

Severity
6
CVSS
(AV:N/AC:M/Au:S/C:N/I:N/A:C)
Published
Oct 28, 2025
Added
Oct 28, 2025
Modified
Oct 30, 2025

Description

If an error occurred (including exceeding limits) during the processing
of a multipart upload, temporary copies of the uploaded parts written to
local storage were not cleaned up immediately but left for the garbage
collection process to delete. Depending on JVM settings, application
memory usage and application load, it was possible that space for the
temporary copies of uploaded parts would be filled faster than GC cleared
it, leading to a DoS.

Solutions

apache-tomcat-upgrade-10_1_47apache-tomcat-upgrade-11_0_12apache-tomcat-upgrade-9_0_110
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.