5.3

CVE-2026-66299

Apache Tomcat: DoS via WebSocket chat example

Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.

This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.

Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Tomcat Version >= 9.0.89 < 9.0.121
Apache ≫ Tomcat Version >= 10.1.24 < 10.1.58
Apache ≫ Tomcat Version >= 11.0.1 < 11.0.25
Apache ≫ Tomcat Version 11.0.0 Update milestone20
Apache ≫ Tomcat Version 11.0.0 Update milestone21
Apache ≫ Tomcat Version 11.0.0 Update milestone22
Apache ≫ Tomcat Version 11.0.0 Update milestone23
Apache ≫ Tomcat Version 11.0.0 Update milestone24
Apache ≫ Tomcat Version 11.0.0 Update milestone25
Apache ≫ Tomcat Version 11.0.0 Update milestone26
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.45% 0.37
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://lists.apache.org/thread/8owczcc1o8qw1rxmg9gvfk4w2jnh4l5k
Vendor Advisory
Mailing List
http://www.openwall.com/lists/oss-security/2026/07/28/25
Third Party Advisory
Mailing List