Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
POC-CVE-2025-48988-CVE-2025-48976 — Proof-of-concept exploit for Tomcat CVEs causing CPU exhaustion via parallel multipart requests, with Docker setup and remediation guidance. | Kitploit
Tools/GitHubGitHub/samb102/poc-cve-2025-48988-cve-2025-48976
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration Testing
GitHubsamb102/poc-cve-2025-48988-cve-2025-48976

POC-CVE-2025-48988-CVE-2025-48976

Proof-of-concept exploit for Tomcat CVEs causing CPU exhaustion via parallel multipart requests, with Docker setup and remediation guidance.

View Repository
221 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-48988 & CVE-2025-48976

About

This project runs a simple file upload endpoint with Tomcat 10.1.41 and a Jakarta Servlet.

The exploit runs, by default, 1000 parallelized multipart requests with 1000 parts and 50 headers by part, from 50 workers.

Run POC

Build and run the Docker container:

docker build -t poc-cve-2025-48988 .

docker run -p 8080:8080 poc-cve-2025-48988

Launch the exploit:

python3 exploit-cve-2025-48988.py

Monitor container resource usage:

docker stats

You will observe a significant increase in CPU usage: Stats

Remediation

Change docker image in dockerfile from tomcat:10.1.41-jdk17 to tomcat:10.1.42-jdk17

With its default configuration, Tomcat will now respond with a 500 status code and CPU usage will remain stable, as per fix introduced in Tomcat 10.1.42.

Download Tool