CVE-2026-66299
published 2026-07-28CVE-2026-66299: Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24…
PriorityP345high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.45%
37.6th percentile
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.
This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.
Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.24 < 10.1.58 | 10.1.58 |
| apache | tomcat | >= 11.0.1 < 11.0.25 | 11.0.25 |
| apache | tomcat | >= 9.0.89 < 9.0.121 | 9.0.121 |
| apache_software_foundation | apache_tomcat | 10.1.24 – 10.1.57 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M20 – 11.0.24 | — |
| apache_software_foundation | apache_tomcat | 9.0.89 – 9.0.120 | — |
| debian | tomcat10 | — | — |
| debian | tomcat11 | — | — |
| debian | tomcat9 | — | — |
| pki-deps_10.6 | pki-servlet-engine | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
tomcat: Apache Tomcat: Denial of Service via WebSocket chat example
vendor_redhat·2026-07-28·CVSS 7.5
CVE-2026-66299 [HIGH] CWE-770 tomcat: Apache Tomcat: Denial of Service via WebSocket chat example
tomcat: Apache Tomcat: Denial of Service via WebSocket chat example
A flaw was found in Apache Tomcat. This uncontrolled resource consumption vulnerability, located in the WebSocket chat example, allows a remote attacker to cause a Denial of Service (DoS) by exhausting system resources. This can lead to the affected system becoming unresponsive or crashing.
Statement: This Moderate severity flaw in Apache Tomcat's WebSocket chat example could lead to a denial of service. The impact is limited as the vulnerable component is part of an example application, which is generally not deployed in production environments. Exploitation requires the example application to be present and accessible.
Mitigation: To mitigate this vulnerability, remove the `examples` web application from your Apache T
GHSA
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.
ghsa_unreviewed·2026-07-28
CVE-2026-66299 [HIGH] CWE-400 Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.
This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.
Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-66299 tomcat: Apache Tomcat: Denial of Service via WebSocket chat example [fedora-all]
bugzilla·2026-08-03·CVSS 7.5
CVE-2026-66299 [HIGH] CVE-2026-66299 tomcat: Apache Tomcat: Denial of Service via WebSocket chat example [fedora-all]
CVE-2026-66299 tomcat: Apache Tomcat: Denial of Service via WebSocket chat example [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.
This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.
Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix t
Bugzilla
CVE-2026-66299 tomcat: Apache Tomcat: Denial of Service via WebSocket chat example
bugzilla·2026-07-28·CVSS 7.5
CVE-2026-66299 [HIGH] CVE-2026-66299 tomcat: Apache Tomcat: Denial of Service via WebSocket chat example
CVE-2026-66299 tomcat: Apache Tomcat: Denial of Service via WebSocket chat example
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.
This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.
Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.
2026-07-28
Published