CVE-2025-53506 | Apache Tomcat up to 9.0.106/10.1.42/11.0.8 HTTP/2 Client resource consumption (EUVD-2025-21032 / Nessus ID 241706)
A vulnerability classified as problematic was found in Apache Tomcat up to 9.0.106/10.1.42/11.0.8. The affected element is an unknown function of the component HTTP2 Client Handler. Executing manipulation can lead to resource consumption.
This vulnerability is handled as CVE-2025-53506. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.