VYPR
Medium severity5.3NVD Advisory· Published Jul 28, 2026· Updated Aug 27, 2026

CVE-2026-66299

CVE-2026-66299

Description

Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.

This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.

Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

12
  • Apache/Tomcat9 versions
    cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*+ 8 more
    • cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*range: >=9.0.89,<9.0.121
    • cpe:2.3:a:apache:tomcat:11.0.0:milestone20:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:11.0.0:milestone21:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:11.0.0:milestone22:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:11.0.0:milestone23:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:11.0.0:milestone24:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:11.0.0:milestone25:*:*:*:*:*:*
    • cpe:2.3:a:apache:tomcat:11.0.0:milestone26:*:*:*:*:*:*
    • (no CPE)range: 11.0.0-M20 - 11.0.24, 10.1.24 - 10.1.57, 9.0.89 - 9.0.120
  • osv-coords3 versions
    < 10.1.59-160000.1.1+ 2 more
    • (no CPE)range: < 10.1.59-160000.1.1
    • (no CPE)range: < 11.0.25-160000.1.1
    • (no CPE)range: < 9.0.121

Patches

Vulnerability mechanics

References

2

News mentions

2