CVE-2026-66299 Details
Description
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue. Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.
A denial-of-service vulnerability has been identified in the WebSocket chat example of Apache Tomcat. This issue affects versions 11.0.0-M20 through 11.0.24, 10.1.24 through 10.1.57, and 9.0.89 through 9.0.120. The vulnerability arises from an unbounded buffer for undelivered messages, allowing a maliciously slow client to cause the buffer to grow indefinitely. This continuous expansion can lead to memory exhaustion, causing the Tomcat process to fail. Users who have removed the examples web application are not affected.
Users of affected versions should either remove the examples web application or upgrade to Apache Tomcat 11.0.25, 10.1.58, or 9.0.121 when these versions are released.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/07/28/25 | CVE | Mailing ListThird Party Advisory |
| https://lists.apache.org/thread/8owczcc1o8qw1rxmg9gvfk4w2jnh4l5k | [email protected] | Mailing ListVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-400 | Uncontrolled Resource Consumption | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| apache tomcat | >= 9.0.89, < 9.0.121 >= 10.1.24, < 10.1.58 >= 11.0.1, < 11.0.25 11.0.0 milestone20 11.0.0 milestone21 11.0.0 milestone22 11.0.0 milestone23 11.0.0 milestone24 11.0.0 milestone25 11.0.0 milestone26 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 27, 2026 | Reanalysis | [email protected] |
| Aug 5, 2026 | Initial Analysis | [email protected] |
| Jul 28, 2026 | CVE Modified | CISA-ADP |
| Jul 28, 2026 | CVE Modified | CVE |
| Jul 28, 2026 | New CVE Received | [email protected] |