7.3
CVE-2026-78437
- EPSS 0.26%
- Veröffentlicht 23.09.2026 11:26:29
- Zuletzt bearbeitet 23.09.2026 19:19:21
- Erkennungen
Apache Tomcat: HTTP/2 DoS via malformed request
Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail. This issue affects Apache Tomcat: from 11.0.19 through 11.0.25, from 10.1.53 through 10.1.59, from 9.0.116 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerApache Software Foundation
≫
Produkt
Apache Tomcat
Default Statusunaffected
Version <=
11.0.25
Version
11.0.19
Status
affected
Version <=
10.1.59
Version
10.1.53
Status
affected
Version <=
9.0.121
Version
9.0.116
Status
affected
Version <=
8.5.100
Version
0
Status
unaffected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.26% | 0.157 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| CISA-ADP | 7.3 | 3.9 | 3.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
|
CWE-459 Incomplete Cleanup
The product does not properly "clean up" and remove temporary or supporting resources after they have been used.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://lists.apache.org/thread/qkmsos3s8chn5053qr466rzwv6sk5gjg
http://www.openwall.com/lists/oss-security/2026/09/23/26