Allocation of Resources Without Limits or Throttling in Apache Tomcat - CVE-2026-66299
Published: July 28, 2026 / Updated: August 25, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in the WebSocket chat example when buffering undelivered messages for a maliciously slow client connection. A remote attacker can maintain a slow client connection to cause a denial of service.
Only deployments exposing the example web application are vulnerable.
Affected software
openEuler
tomcat
tomcat-help
tomcat-jsvc
How to mitigate CVE-2026-66299
tomcat - update to 9.0.120-2
tomcat-help - update to 9.0.120-2
tomcat-jsvc - update to 9.0.120-2
External References
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.25
- https://github.com/apache/tomcat/commit/4e8e3f8964e9653bab427bf794e026c69ee80f2b
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.58
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.121
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.59