Release Notes
Complete Changelog for NES for Tomcat
Tomcat 8.5.x
8.5.101 (NES) - July 10, 2025
Notes
- This release originates from the open‑source Apache Tomcat project forked by HeroDevs. It encompasses modifications implemented by HeroDevs to ensure successful framework builds.
- This release includes both maven packages and binaries. The binary packages for this release are available at
https://registry.nes.herodevs.com/bin/org.apache.tomcat/tomcat-release/8.5.100-tomcat-8.5.101/tomcat-nes-v8.5.101.zip
.
Bug Fixes
- Make counting of active streams more robust
- This fixes a High Severity Denial of Service vulnerability CVE-2024-34750
- Add support for re-keying with TLS 1.3
- This fixes a High Severity Denial of Service vulnerability CVE-2024-38286
- Fix inconsistent resource metadata with current GET and PUT/DELETE
- This fixes a High Severity Remote Code Execution vulnerability CVE-2024-50379
- If the Jakarta Authentication fails with an exception, set a 500 status
- This fixes a Critical Severity Authorization Bypass vulnerability CVE-2024-52316
- Fix Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service.
- This fixes a Medium Severity Denial of Service vulnerability CVE-2024-54677
- Automate protection for CVE-2024-56337
- This fixes a High Severity Remote Code Execution vulnerability CVE-2024-56337
- Enhance lifecycle of temporary files used by partial PUT
- This fixes a Critical Severity Remote Code Execution vulnerability CVE-2025-24813
- Fix Apache Tomcat Denial of Service via invalid HTTP priority header
- This fixes a High Severity Denial of Service vulnerability CVE-2025-31650
- Fix Apache Tomcat Rewrite rule bypass
- This fixes a Critical Severity Authorization Bypass vulnerability CVE-2025-31651
- Refactor CGI servlet to access resources via WebResources and Use WebResource API to differentiate files and directories
- This fixes a High Severity Authorization Bypass vulnerability CVE-2025-46701
- Fix Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload.
- This fixes a High Severity Denial of Service vulnerability CVE-2025-48976
- Fix Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
- This fixes a High Severity Denial of Service vulnerability CVE-2025-48988
- Use the full path when calling icacls.exe
- This fixes a High Severity Untrusted Search Path vulnerability CVE-2025-49124
- Expand checks for webAppMount
- This fixes a High Severity Authentication Bypass vulnerability CVE-2025-49125
Full Version: 8.5.100-tomcat-8.5.101