Denial of Service Vulnerability in Apache Tomcat by Apache
CVE-2026-79677

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-79677?

A resource management vulnerability in Apache Tomcat can cause a denial of service due to the failure to release resources after their effective lifetime. This issue affects asynchronous WebSocket communications, potentially leading to lost timeouts. Users running versions from 11.0.0-M1 to 11.0.25, 10.1.0-M1 to 10.1.59, and 9.0.0-M1 to 9.0.121 are impacted. Older versions such as 8.5.0 to 8.5.100 and 7.0.43 to 7.0.109 are also affected. It is advisable for users to upgrade to the patched versions 11.0.26, 10.1.60, or 9.0.122 to mitigate this risk.

Affected Version(s)

Apache Tomcat 11.0.0-M1 <= 11.0.25

Apache Tomcat 10.1.0-M1 <= 10.1.59

Apache Tomcat 9.0.0.M1 <= 9.0.121

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.