Denial of Service Vulnerability in Apache Tomcat Affecting Multiple Versions
CVE-2026-78383

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-78383?

A resource allocation issue in Apache Tomcat permits unauthenticated AJP requests to monopolize a processing thread. This can lead to a denial of service, impacting the availability of the server. It is recommended that users upgrade to fixed versions: 11.0.26, 10.1.60, or 9.0.122 to mitigate this vulnerability.

Affected Version(s)

Apache Tomcat 11.0.0-M1 <= 11.0.25

Apache Tomcat 10.1.0-M1 <= 10.1.59

Apache Tomcat 9.0.0.M1 <= 9.0.121

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.