Back

HIGH

Apache Tomcat: DoS via busy wait during WebSocket close

Published Sep 23, 2026

Description

Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS attack.

This issue affects Apache Tomcat: from 11.0.0-M5 through 11.0.25, from 10.1.8 through 10.1.59, from 9.0.74 through 9.0.121.

The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.88 through 8.5.100. Other unsupported versions may also be affected.

Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Sep 23, 2026
Updated Sep 23, 2026
Reserved Aug 21, 2026
CISA Vulnrichment
Updated Sep 23, 2026
NVD
Status Awaiting Analysis
Modified Sep 23, 2026
Red Hat
Severity n/a
Public date n/a