Apache Tomcat Security Update Advisory (CVE-2026-66299)
Overview
An update advisory regarding a security vulnerability in Apache Tomcat has been issued.
Vulnerability Details
- The vulnerability identifier is
CVE-2026-66299. - The vulnerability is a denial-of-service (
DoS, a condition that disrupts normal service) vulnerability caused by uncontrolled resource consumption in Apache Tomcat’sWebSocket(real-time bidirectional communication feature) chat example.
Affected Versions
- Apache Tomcat
9.0.89Through9.0.120. - Apache Tomcat
10.1.24Through10.1.57. - Apache Tomcat
11.0.0-M20or higher, but no higher than11.0.24.
Mitigation Measures
The Vulnerability Patch has been released via the latest updates.
- Apache Tomcat
9.0.121Or higher. - Apache Tomcat
10.1.58Or later. - Apache Tomcat
11.0.25Or later.
Instructions were provided to update to the latest version with the Vulnerability Patch, following the guidance on the reference website.