Description
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue. Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.
References (2)
Core 2
Core References
Vendor Advisory vendor-advisory
https://lists.apache.org/thread/8owczcc1o8qw1rxmg9gvfk4w2jnh4l5k
Scores
CVSS v3
7.5
EPSS
0.0031
EPSS Percentile
23.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-400
Status
published
Products (4)
Apache Software Foundation/Apache Tomcat
< 8.5.100
Apache Software Foundation/Apache Tomcat
10.1.24 - 10.1.57
Apache Software Foundation/Apache Tomcat
11.0.0-M20 - 11.0.24
Apache Software Foundation/Apache Tomcat
9.0.89 - 9.0.120
Published
Jul 28, 2026
Tracked Since
Jul 28, 2026