Tomcat Flaw Lets Hackers Crash Sites With HTTP/2 Flood
A newly disclosed vulnerability in Apache Tomcat’s Coyote engine, tracked as CVE-2025-53506, exposes servers to denial-of-service attacks via HTTP/2 traffic. The Tomcat flaw lets hackers exploit a loophole where the server fails to cap concurrent streams when a client ignores the SETTINGS frame. Attackers can then flood the server with persistent streams, overwhelming its thread […]
