Resource exhaustion in Apache Tomcat - CVE-2026-78437
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause another user's request to fail.
The vulnerability exists due to improper handling of malformed HTTP/2 requests in HTTP/2 request processing when handling a malformed HTTP/2 request. A remote attacker can send a malformed HTTP/2 request to cause another user's request to fail.
Successful exploitation depends on timing.