PatchSiren cyber security CVE debrief
CVE-2026-66299 Apache CVE debrief
Apache Tomcat has an Uncontrolled Resource Consumption vulnerability in its WebSocket chat example, affecting versions 11.0.0-M20 through 11.0.24, 10.1.24 through 10.1.57, and 9.0.89 through 9.0.120. Users who have removed the examples web application are not affected. The issue is fixed in versions 11.0.25, 10.1.58, and 9.0.121. This vulnerability can lead to resource exhaustion, posing a significant risk to users of affected versions. It is crucial for users to review their deployments and plan for mitigation or remediation. The CVE record and NVD detail page provide critical information for understanding the vulnerability and planning mitigation efforts.
- Vendor
- Apache
- Product
- Tomcat
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-28
- Original CVE updated
- 2026-08-05
- Advisory published
- 2026-07-28
- Advisory updated
- 2026-08-05
Who should care
Users of Apache Tomcat, especially those using the WebSocket chat example, should be aware of this vulnerability and take action to mitigate it. This includes users of affected versions who have not removed the examples web application. Operators, platform administrators, vulnerability management teams, and security teams should review the affected versions and plan for mitigation or remediation. Those using WebSocket functionality should prioritize review and mitigation efforts due to the potential for resource exhaustion. Review of WebSocket configuration and resource limits is also recommended to ensure optimal resource usage and minimize potential impact. Monitoring for unusual WebSocket activity can help detect potential exploitation attempts. Asset inventory and change management processes should also be reviewed to ensure timely detection and remediation of affected systems. Compensating controls, such as implementing resource limits for WebSocket connections, may be necessary while remediation is scheduled and verified. Tracking exceptions, retesting remediated assets, and documenting evidence are crucial for closure. This vulnerability's high CVSS score of 7.5 indicates a high severity, warranting immediate attention from affected users. The vulnerability's potential for resource exhaustion makes it critical for users to review and adjust WebSocket configuration for optimal resource usage. Users should also consider compensating controls for exposed systems while remediation is scheduled and verified. Monitoring and detection capabilities should be reviewed to ensure they can identify potential exploitation attempts. The CVE record and NVD detail page provide critical information for understanding the vulnerability and planning mitigation efforts. Users should assign an owner for follow-up and review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance. Planning vendor-supported updates or mitigations through normal change control where exposure is confirmed is essential. Reviewing compensating controls for exposed systems while remediation is scheduled and verified can help minimize potential impact. In
Technical summary
The Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example can lead to resource exhaustion. Affected versions include 11.0.0-M20 through 11.0.24, 10.1.24 through 10.1.57, and 9.0.89 through 9.0.120. The vulnerability is addressed in versions 11.0.25, 10.1.58, and 9.0.121. This issue arises from the WebSocket chat example's inability to properly limit resource usage, which can be exploited to cause a denial-of-service condition. Users should review their WebSocket configuration and consider implementing resource limits for WebSocket connections to mitigate the risk.
Defensive priority
High priority due to high CVSS score of 7.5 and potential for resource exhaustion
Recommended defensive actions
- Remove the examples web application if not required
- Upgrade to version 11.0.25, 10.1.58, or 9.0.121 when available
- Monitor for unusual WebSocket activity
- Implement resource limits for WebSocket connections
- Review and adjust WebSocket configuration for optimal resource usage
Evidence notes
Evidence from official CVE and NVD sources indicate an Uncontrolled Resource Consumption vulnerability exists in Apache Tomcat's WebSocket chat example. Affected versions are well-documented, and fixes are provided. Users who removed the examples web application are not affected. To verify, defenders should review the official CVE record and NVD detail page for accuracy and check their deployments against the affected versions. Additional verification may be necessary to confirm the scope of exposure.
Official resources
-
CVE-2026-66299 CVE record
CVE.org
-
CVE-2026-66299 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Mailing List, Vendor Advisory
-
Mitigation or vendor reference
af854a3a-2127-422b-91ae-364da2661108 - Mailing List, Third Party Advisory
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-28T15:17:50.210Z and has not been modified since then. The NVD entry is currently Analyzed.