CVE-2026-41284 Details
Description
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117. Older, unsupported versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
A vulnerability allowing unbounded resource allocation has been identified in Apache Tomcat's WebDAV LOCK and PROPFIND request handling. This issue affects Apache Tomcat versions 11.0.0-M1 prior to 11.0.21, 10.1.0-M1 prior to 10.1.54, and 9.0.0-M1 prior to 9.0.117. Older, unsupported versions may also be affected. The vulnerability arises because no limit was imposed on the request body for WebDAV LOCK or PROPFIND requests, which were accessible to unauthenticated users.
Users should upgrade to Apache Tomcat 11.0.22 or later, 10.1.55 or later, or 9.0.118 or later.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/05/12/12 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/2nvqjr7ovjmvx2vbhb7s61ycd5msc8qc | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache tomcat | >= 4.0.0, <= 7.0.109 >= 8.5.0, <= 8.5.100 >= 9.0.0, < 9.0.118 >= 10.0.0, <= 10.0.27 >= 10.1.0, < 10.1.55 >= 11.0.0, < 11.0.22 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 14, 2026 | Initial Analysis | [email protected] |
| May 13, 2026 | CVE Modified | CISA-ADP |
| May 12, 2026 | CVE Modified | CVE |
| May 12, 2026 | New CVE Received | [email protected] |