7.5

CVE-2026-66299

Apache Tomcat: DoS via WebSocket chat example

Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.

This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.

Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ApacheTomcat Version >= 9.0.89 < 9.0.121
ApacheTomcat Version >= 10.1.24 < 10.1.58
ApacheTomcat Version >= 11.0.1 < 11.0.25
ApacheTomcat Version11.0.0 Updatemilestone20
ApacheTomcat Version11.0.0 Updatemilestone21
ApacheTomcat Version11.0.0 Updatemilestone22
ApacheTomcat Version11.0.0 Updatemilestone23
ApacheTomcat Version11.0.0 Updatemilestone24
ApacheTomcat Version11.0.0 Updatemilestone25
ApacheTomcat Version11.0.0 Updatemilestone26
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.37
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://lists.apache.org/thread/8owczcc1o8qw1rxmg9gvfk4w2jnh4l5k
Vendor Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2026/07/28/25
Third Party Advisory
Mailing List