StackRadar

CVE-2025-53506

High

Advisory

Published 10 Jul 2025In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
7.5
base score, highest
EPSS
0.020
80th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
271
of 17,781 indexed, latest versions
Container images
225
deployed by those charts
Fix available
4 of 4
affected packages

Apache Tomcat: DoS via excessive h2 streams at connection start

Carried by container images the latest versions of 271 of 17,781 indexed charts deploy, on 225 images.

Affected packageAffected versionsFixed inImages
tomcat-embed-coremaven8.5.4, 8.5.11, 8.5.14, 8.5.15+68 more9.0.107, 10.1.43, 11.0.9206
tomcat-coyotemaven8.5.38, 8.5.41, 8.5.43, 8.5.57+16 more9.0.107, 10.1.43, 11.0.923
Apache Tomcatbitnami9.0.809.0.1071
tomcatbitnami9.0.80-19.0.1071
OSV records
BIT-tomcat-2025-53506GHSA-25xr-qj8w-c4vf

Charts affected

271 by stars
ChartLatestAffected imagesRadar Score
tmdbluiscajl0.2.41 of 1See more

tmdb luiscajl 0.2.4

1 of the 1 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
lavandadelpatio/tmdb:latestded9377636e9
tomcat-embed-core@10.1.15
10.1.43

Open the chart page →

2,234
torznab-atomohdluiscajl0.0.31 of 1See more

torznab-atomohd luiscajl 0.0.3

1 of the 1 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
lavandadelpatio/torznab-atomohd:latest214eaef5444c
tomcat-embed-core@10.1.7
10.1.43

Open the chart page →

3,290
resource-processormicroservices-learningVerified publisher1.2.01 of 1See more

resource-processor microservices-learning 1.2.0

1 of the 1 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-processor:latest64a25afb8748
tomcat-embed-core@10.1.13
10.1.43

Open the chart page →

3,683
resource-servicemicroservices-learningVerified publisher1.5.01 of 2See more

resource-service microservices-learning 1.5.0

1 of the 2 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.resource-service:latest13ad9bb170a0
tomcat-embed-core@10.1.13
10.1.43

Open the chart page →

5,129
song-servicemicroservices-learningVerified publisher1.2.01 of 2See more

song-service microservices-learning 1.2.0

1 of the 2 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
maksimkavalenka/microservices-learning.song-service:latest2bcdac368b07
tomcat-embed-core@10.1.13
10.1.43

Open the chart page →

4,599
unifimidokura-communityVerified publisher0.0.61 of 1See more

unifi midokura-community 0.0.6

1 of the 1 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
linuxserver/unifi-controller:7.3.83ab105cc50322
tomcat-embed-core@9.0.59
9.0.107

Open the chart page →

11,188
pulsarv2milvus-helm2.7.81 of 4See more

pulsarv2 milvus-helm 2.7.8

1 of the 4 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
apachepulsar/pulsar-manager:v0.1.0b341ef76a852
tomcat-embed-core@8.5.31
no fix listed

Open the chart page →

15,855
mitre-siphonmitre-siphon0.2.91 of 4See more

mitre-siphon mitre-siphon 0.2.9

1 of the 4 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
tomcat-embed-core@10.1.8
10.1.43

Open the chart page →

3,083
crowdmoxVerified publisher2.4.31 of 3See more

crowd mox 2.4.3

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
atlassian/crowd:5.2.2ebf761c7d437
tomcat-coyote@9.0.82
9.0.107

Open the chart page →

5,663
devops-demomungari-development-charts1.0.41 of 4See more

devops-demo mungari-development-charts 1.0.4

1 of the 4 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
tomcat-embed-core@9.0.65
9.0.107

Open the chart page →

8,928
pagesmuthu-pages1.0.01 of 3See more

pages muthu-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
myappmyapp-helm-charts0.4.01 of 1See more

myapp myapp-helm-charts 0.4.0

1 of the 1 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
adityaprasadpathak/myapp:3.07e3b9777362c
tomcat-embed-core@10.1.25
10.1.43

Open the chart page →

2,141
nacosnacos-yunyeVerified publisher1.0.31 of 1See more

nacos nacos-yunye 1.0.3

1 of the 1 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
nacos/nacos-server:v3.0.130a39cb0c54d
tomcat-embed-core@10.1.39
10.1.43

Open the chart page →

1,783
pagesnarain1.0.01 of 3See more

pages narain 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
pagesnarasimha-pages1.0.01 of 3See more

pages narasimha-pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
pagesnavin-brixton1.0.01 of 3See more

pages navin-brixton 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
config-server-helm-chartnotesprojectchart0.1.01 of 1See more

config-server-helm-chart notesprojectchart 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
vlebediantsev/config-server-another:lateste7f20450d2ae
tomcat-embed-core@9.0.65
9.0.107

Open the chart page →

3,422
file-system-ms-helm-chartnotesprojectchart0.1.01 of 2See more

file-system-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
vlebediantsev/file-system-ms-final:latest10393a89b4a8
tomcat-embed-core@9.0.64
9.0.107

Open the chart page →

5,875
logic-ms-helm-chartnotesprojectchart0.1.01 of 2See more

logic-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
vlebediantsev/logic-ms:latestdf8bf38c535b
tomcat-embed-core@9.0.64
9.0.107

Open the chart page →

6,852
registration-ms-helm-chartnotesprojectchart0.1.01 of 2See more

registration-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
vlebediantsev/registration-ms-final:latest427af418b75e
tomcat-embed-core@9.0.64
9.0.107

Open the chart page →

5,916
user-data-ms-helm-chartnotesprojectchart0.1.01 of 2See more

user-data-ms-helm-chart notesprojectchart 0.1.0

1 of the 2 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
vlebediantsev/user-data-ms-final-final:latest9319437f3c8f
tomcat-embed-core@9.0.64
9.0.107

Open the chart page →

5,873
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
tomcat-coyote@8.5.38
tomcat-embed-core@8.5.38
no fix listed
no fix listed

Open the chart page →

63,223
ves-agentopencord1.0.21 of 1See more

ves-agent opencord 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
opencord/ves-agent:1.0.04187e2a8c918
tomcat-embed-core@8.5.31
no fix listed

Open the chart page →

6,350
bpjstk-serviceopenshift1.0.05 of 6See more

bpjstk-service openshift 1.0.0

5 of the 6 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
andrianrf/backoffice-be:latest6036614803d4
tomcat-embed-core@9.0.75
9.0.107
andrianrf/bpjstk-service:latest46abe878d9d8
tomcat-embed-core@9.0.38
9.0.107
andrianrf/bpjstk-simulator:latestb63fdb51d39d
tomcat-embed-core@9.0.38
9.0.107
andrianrf/iso-client:latestba560086ce15
tomcat-embed-core@9.0.38
9.0.107
andrianrf/iso-server:latest7da47f525c7d
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

34,671
fineractopenshift0.1.11 of 4See more

fineract openshift 0.1.1

1 of the 4 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
apache/fineract:1.12.1a83cf1980609
tomcat-embed-core@10.1.39
10.1.43

Open the chart page →

7,792
redhat-springboot-restopenshift0.0.11 of 1See more

redhat-springboot-rest openshift 0.0.1

1 of the 1 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
tomcat-embed-core@9.0.83
9.0.107

Open the chart page →

3,063
smsf-configurationopenshift1.0.41 of 1See more

smsf-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
gurolakman/smsf-configuration:1.0.49abb3882bcbd
tomcat-embed-core@9.0.60
9.0.107

Open the chart page →

13,607
smsf-momtopenshift1.0.41 of 1See more

smsf-momt openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
gurolakman/smsf-momt:1.0.4ce23b20a8a17
tomcat-embed-core@9.0.60
9.0.107

Open the chart page →

13,568
smsf-registrationopenshift1.0.41 of 1See more

smsf-registration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
gurolakman/smsf-registration:1.0.4b22e746edd5d
tomcat-embed-core@9.0.60
9.0.107

Open the chart page →

13,551
ussigw-configurationopenshift1.0.41 of 1See more

ussigw-configuration openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
gurolakman/ussigw-configuration:1.0.4bf18525c5ad9
tomcat-embed-core@9.0.60
9.0.107

Open the chart page →

13,455
ussigw-coreopenshift1.0.41 of 1See more

ussigw-core openshift 1.0.4

1 of the 1 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
gurolakman/ussigw-core:1.0.48739565c3ea2
tomcat-embed-core@9.0.60
9.0.107

Open the chart page →

13,100
operatonoperatonVerified publisher1.0.51 of 1See more

operaton operaton 1.0.5

1 of the 1 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
operaton/operaton:1.0.0-beta-4b35867ffe4d8
tomcat-embed-core@10.1.39
10.1.43

Open the chart page →

2,003
issuegenopsmxVerified publisher1.0.21 of 1See more

issuegen opsmx 1.0.2

1 of the 1 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
opsmx11/issuegen:v2.1.05c50ca123d88
tomcat-embed-core@9.0.26
9.0.107

Open the chart page →

26,339
pagespages1.0.01 of 3See more

pages pages 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
pagespages-10.1.01 of 1See more

pages pages-1 0.1.0

1 of the 1 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:1.04d2eb25b9225
tomcat-embed-core@9.0.43
9.0.107

Open the chart page →

10,392
pagespages101.0.01 of 3See more

pages pages10 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
pagespages1111.0.01 of 3See more

pages pages111 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
pagespages21.0.01 of 3See more

pages pages2 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
pagespages-alexchmielu1.0.01 of 3See more

pages pages-alexchmielu 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
pagespages-alps1.0.01 of 3See more

pages pages-alps 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
pagespages-alstom1.0.01 of 3See more

pages pages-alstom 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
pagespages-ambala1.0.01 of 3See more

pages pages-ambala 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
pagespages-andromeda1.0.01 of 3See more

pages pages-andromeda 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
pagespagesbadami1.0.01 of 3See more

pages pagesbadami 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
pagespages-blackburn1.0.01 of 3See more

pages pages-blackburn 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
pagespages-botes1.0.01 of 3See more

pages pages-botes 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
pagespages-brian1.0.01 of 3See more

pages pages-brian 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
pagespages-buckll1.0.01 of 3See more

pages pages-buckll 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
pagespages-camden1.0.01 of 3See more

pages pages-camden 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190
pagespages-camden7711.0.01 of 3See more

pages pages-camden771 1.0.0

1 of the 3 container images this version deploys carry CVE-2025-53506.

Container imageDigestPackageFixed in
dellcloud/pages:monitor6ba7b22caacd
tomcat-embed-core@9.0.36
9.0.107

Open the chart page →

20,190

Container images carrying it

225 by charts deploying them

A fixed version is listed for 4 of the 4 affected packages.

Container imageDigestPackageFixed inUsed by
vrijbrp/balie:developbc85c89530b9
tomcat-coyote@9.0.84
9.0.107
1
vrijbrp/balie-ws:developc6603cb829ea
tomcat-coyote@9.0.84
9.0.107
1
vrijbrp/haal-centraal-brp-bevragen:develop5c770c2ae48c
tomcat-embed-core@9.0.74
9.0.107
1
xuxueli/xxl-job-admin:2.4.0640093c35fd6
tomcat-embed-core@9.0.71
9.0.107
1
zahoriaut/zahori-process:0.1.13351f8a220ed7
tomcat-embed-core@10.1.10
10.1.43
1
zahoriaut/zahori-server:0.1.17b2de13916f3e
tomcat-embed-core@9.0.71
9.0.107
1
gcr.io/spinnaker-marketplace/halyard:1.32.00ee5f968d2ab
tomcat-embed-core@9.0.30
9.0.107
1
ghcr.io/camunda-community-hub/zeebe-simple-monitor:2.6.2d9d796a1b846
tomcat-embed-core@10.1.17
10.1.43
1
ghcr.io/curium-rocks/mitre-siphon:main503c00321502
tomcat-embed-core@10.1.8
10.1.43
1
ghcr.io/it-at-m/appswitcher-server:1.3.010006bc0f309
tomcat-embed-core@10.1.40
10.1.43
1
ghcr.io/it-at-m/zammad-ldap-sync:dev10de22c8cbce
tomcat-embed-core@10.1.34
10.1.43
1
ghcr.io/jfwenisch/steamcmd-manager:v0.4.5dab685e668d9
tomcat-embed-core@10.1.33
10.1.43
1
ghcr.io/jfwenisch/webtools:v0.1.44569cae83c70
tomcat-embed-core@10.1.33
10.1.43
1
ghcr.io/k8s-at-home/nzbhydra2:v3.14.2ef3670f7e0a8
tomcat-embed-core@9.0.36
9.0.107
1
ghcr.io/linuxserver/booksonic-air:version-v2009.1.0baa4fa9549dc
tomcat-embed-core@9.0.37
9.0.107
1
ghcr.io/perceptolab/devops-demo-app:0.0.2cdc0658c40fb
tomcat-embed-core@9.0.65
9.0.107
1
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
tomcat-embed-core@9.0.21
9.0.107
1
ghcr.io/star-whale/server:0.6.158368359c8dd0
tomcat-embed-core@9.0.70
9.0.107
1
quay.io/freeipa/freeipa-server:fedora-39-4.11.1d422ee50c2c3
tomcat-coyote@9.0.83
9.0.107
1
quay.io/opsmxpublic/ubi8-gate:isd-spin-2025.10.01-5c720954-2025112608102b3554029737
tomcat-embed-core@10.1.16
10.1.43
1
quay.io/opsmxpublic/ubi8-oes-audit-client:isd-spin-2025.10.01-cb1bfce-20251126103732a5b1887eab
tomcat-embed-core@10.1.18
10.1.43
1
quay.io/opsmxpublic/ubi8-oes-autopilot:isd-spin-2025.10.01-af26a30d4-20251126105458bd0bcf72f9
tomcat-embed-core@10.1.18
10.1.43
1
quay.io/opsmxpublic/ubi8-oes-platform:isd-spin-2025.10.01-a7c191ec-2025112611228ed603ab7417
tomcat-embed-core@10.1.18
10.1.43
1
quay.io/snowdrop/spring-boot-rest-http-example:2.7b1a054613715
tomcat-embed-core@9.0.83
9.0.107
1
quay.io/srcmaxim/gradle-example-app:1.1.37c3fc28746ef
tomcat-embed-core@9.0.46
9.0.107
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.