All,
You may have already come across this, but Apache Tomcat has had a major RCE (Remove Code Execution) vulnerability (CVE-2025-24813) announced within the last week, and exploits are already occurring.
While not all installations of Tomcat may be impacted, it is important for all DSpace sites (which often use Tomcat) review the vulnerability information and/or consider an immediate upgrade to your Tomcat installation.
Vulnerable versions of Tomcat include 9.0.0.M1 to 9.0.98, 10.1.0-M1 to 10.1.34, and 11.0.0-M1 to 11.0.2.
You are NOT impacted if you are already running Tomcat 9.0.99, 10.1.35 or 11.0.3 (or any later Tomcat release).
For more information see these resources:
Tim