Apache Tomcat Security Update Advisory (CVE-2026-66299)

Apache Tomcat Security Update Advisory (CVE-2026-66299)

Overview

An update advisory regarding a security vulnerability in Apache Tomcat has been issued.

Vulnerability Details

  • The vulnerability identifier is CVE-2026-66299.
  • The vulnerability is a denial-of-service (DoS, a condition that disrupts normal service) vulnerability caused by uncontrolled resource consumption in Apache Tomcat’s WebSocket (real-time bidirectional communication feature) chat example.

Affected Versions

  • Apache Tomcat 9.0.89 Through 9.0.120.
  • Apache Tomcat 10.1.24 Through 10.1.57.
  • Apache Tomcat 11.0.0-M20 or higher, but no higher than 11.0.24.

Mitigation Measures

The Vulnerability Patch has been released via the latest updates.

  • Apache Tomcat 9.0.121 Or higher.
  • Apache Tomcat 10.1.58 Or later.
  • Apache Tomcat 11.0.25 Or later.

Instructions were provided to update to the latest version with the Vulnerability Patch, following the guidance on the reference website.