StackRadar

CVE-2025-52520

High

Advisory

Published 10 Jul 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.021
80th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
253
of 17,781 indexed, latest versions
Container images
207
deployed by those charts
Fix available
3 of 4
affected packages

Apache Tomcat: DoS via integer overflow in multipart file upload

Carried by container images the latest versions of 253 of 17,781 indexed charts deploy, on 207 images.

Affected packageAffected versionsFixed inImages
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+68 more9.0.107, 10.1.43, 11.0.9206
tomcat-catalinamaven8.5.38, 8.5.82no fix listed2
Apache Tomcatbitnami9.0.809.0.1071
tomcatbitnami9.0.80-19.0.1071
OSV records
BIT-tomcat-2025-52520GHSA-wr62-c79q-cv37

Charts affected

253 by stars
ChartLatestAffected imagesRadar Score
sonarqubewebencryptor6.7.31 of 3See more

sonarqube webencryptor 6.7.3

1 of the 3 container images this version deploys carry CVE-2025-52520.

Container imageDigestPackageFixed in
library/sonarqube:8.2-communitya246bc64207e
tomcat-embed-core@8.5.41
no fix listed

Open the chart page →

5,460
zahori-processzahoriVerified publisher1.0.11 of 1See more

zahori-process zahori 1.0.1

1 of the 1 container images this version deploys carry CVE-2025-52520.

Container imageDigestPackageFixed in
zahoriaut/zahori-process:0.1.13351f8a220ed7
tomcat-embed-core@10.1.10
10.1.43

Open the chart page →

3,480
zahori-serverzahoriVerified publisher1.0.11 of 2See more

zahori-server zahori 1.0.1

1 of the 2 container images this version deploys carry CVE-2025-52520.

Container imageDigestPackageFixed in
zahoriaut/zahori-server:0.1.17b2de13916f3e
tomcat-embed-core@9.0.71
9.0.107

Open the chart page →

5,846

Container images carrying it

207 by charts deploying them

A fixed version is listed for 3 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
ghcr.io/star-whale/server:0.6.158368359c8dd0
tomcat-embed-core@9.0.70
9.0.107
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
tomcat-embed-core@10.1.16
10.1.43
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
tomcat-embed-core@10.1.18
10.1.43
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
tomcat-embed-core@10.1.18
10.1.43
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
tomcat-embed-core@10.1.18
10.1.43
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
tomcat-embed-core@9.0.83
9.0.107
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
tomcat-embed-core@9.0.46
9.0.107
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.