Resource exhaustion in Apache Tomcat - CVE-2026-78383
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of requests without a body in AJP request processing when processing an AJP request without a request body. A remote attacker can send an AJP request without a request body to cause a denial of service.
An affected request can pin an AJP processing thread.