MGASA-2025-0250
Advisory lineage Upstream: 3 Downstream: 0
Published: 29 Oct 2025, 04:28
Last modified:16 Apr 2026, 04:21
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
29 Oct 2025, 04:28
Published
Vulnerability first disclosed
16 Apr 2026, 04:21
Last Modified
Vulnerability information updated
Description
Updated tomcat packages fix security vulnerabilities Directory traversal via rewrite with possible RCE if PUT is enabled. (CVE-2025-55752) Console manipulation via escape sequences in log messages. (CVE-2025-55754) Delayed cleaning of multi-part upload temporary files may lead to DoS. (CVE-2025-61795)
Affected Systems
- mageia•tomcat
< 9.0.111-1.mga9