SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-66299

HIGH · CVSS 7.5 EPSS 0.45%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

Apache Tomcat's WebSocket chat example is vulnerable to uncontrolled resource consumption, potentially allowing an attacker to exhaust server resources. This high-severity issue impacts versions 11.0.0-M20 through 11.0.24, 10.1.24 through 10.1.57, and 9.0.89 through 9.0.120, particularly affecting users who have not removed the examples web application. Organizations using these versions should prioritize immediate removal of the examples or upgrade to the patched versions to mitigate the risk.

CVE
CVE-2026-66299
Severity
HIGH
CVSS
7.5
EPSS
0.45%
Apache

Original NVD Description

Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue. Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.

Related CVEs

Other vulnerabilities affecting the same vendor(s)