OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-77791

HIGH · CVSS 7.5 EPSS 0.53%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Apache Tomcat versions 11.0.0-M5 to 11.0.25, 10.1.8 to 10.1.59, and 9.0.74 to 9.0.121 are vulnerable to an uncontrolled resource consumption issue that can be exploited to launch a denial-of-service (DoS) attack via WebSocket close messages. Organizations using these affected versions should prioritize upgrading to 11.0.26, 10.1.60, or 9.0.122 to mitigate this high-severity vulnerability and protect their services from potential disruptions. Additionally, users of end-of-life versions 8.5.88 to 8.5.100 should be aware that they may also be impacted.

CVE
CVE-2026-77791
Severity
HIGH
CVSS
7.5
EPSS
0.53%
Apache

Original NVD Description

Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS attack. This issue affects Apache Tomcat: from 11.0.0-M5 through 11.0.25, from 10.1.8 through 10.1.59, from 9.0.74 through 9.0.121. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.88 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.