Uncontrolled Resource Consumption in Apache Tomcat's WebSocket Chat Example
CVE-2026-66299

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
28 July 2026

What is CVE-2026-66299?

An uncontrolled resource consumption vulnerability exists in the WebSocket chat example provided with specific versions of Apache Tomcat. This flaw could allow attackers to exploit the resource handling capacity of the server, leading to potential service degradation. It is crucial for users to either remove the examples web application entirely or upgrade their installations to the patched versions. The versions to upgrade to include 11.0.25, 10.1.58, and 9.0.121. Users who have already followed Apache's security guidance regarding the removal of the examples are not affected.

Affected Version(s)

Apache Tomcat 11.0.0-M20 <= 11.0.24

Apache Tomcat 10.1.24 <= 10.1.57

Apache Tomcat 9.0.89 <= 9.0.120

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

4ra1n, pyn3rd and unam4
.