RHSA-2025:22924HighCVSS 7.5

Red Hat Security Advisory: Red Hat JBoss Web Server 5.8.6 release and security update

Published
December 9, 2025
Last Modified
August 4, 2026

🔗 CVE IDs covered (3)

📋 Description

CVE-2025-31651 — tomcat: Apache Tomcat: Bypass of rules in Rewrite Valve CVE-2025-48989 — tomcat: http/2 "MadeYouReset" DoS attack through HTTP/2 control frames CVE-2025-55752 — tomcat: org.apache.tomcat/tomcat-catalina: Apache Tomcat: Directory traversal via rewrite with possible RCE

🎯 Affected products1

  • Red Hat JBoss Web Server 5.8.6

✅ Remediation

Before applying the update, back up your existing Red Hat JBoss Web Server installation, including all applications and configuration files. The References section of this erratum contains a download link for the update. You must be logged in to download the update. Workaround: No mitigation is currently available that meets Red Hat Product Security’s standards for usability, deployment, applicability, or stability. Workaround: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability. To reduced the risk, by disabling or strictly limiting the use of HTTP PUT requests to trusted, authenticated users only. Additionally, administrators should review and adjust URL rewrite rules to ensure they do not manipulate request paths in ways that could expose protected directories such as /WEB-INF/ or /META-INF/. Implementing strict access controls and monitoring for unexpected rewrite or upload behavior can further minimize potential exploitation.

🔗 References (7)