Allocation of Resources Without Limits or Throttling in Apache Tomcat - CVE-2026-66299
Published: July 28, 2026 / Updated: July 28, 2026
Apache Tomcat
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper resource management in the WebSocket chat example when buffering undelivered messages for a maliciously slow client connection. A remote attacker can maintain a slow client connection to cause a denial of service.
Only deployments exposing the example web application are vulnerable.