Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.
This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106.
Users are recommended to upgrade to version 9.0.107, which fixes the issue.
{ "cwe_ids": [ "CWE-362" ], "github_reviewed_at": "2025-07-10T22:55:26Z", "severity": "MODERATE", "github_reviewed": true, "nvd_published_at": "2025-07-10T19:15:25Z" }