[CIVN-2026-0382] Apache Tomcat Denial-of-Service (DoS) Vulnerability in WebSocket Chat Example

By Published On: July 31, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Apache Tomcat Denial-of-Service (DoS) Vulnerability in WebSocket Chat Example


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: MEDIUM


Software Affected


Apache Tomcat version 11.0.0-M20 through 11.0.24

Apache Tomcat version 10.1.24 through 10.1.57

Apache Tomcat version 9.0.89 through 9.0.120

Overview


A vulnerability has been reported in Apache Tomcat that could allow an attacker to cause a denial-of-service (DoS) condition by exploiting the WebSocket chat example application.


Target Audience:

All end-user organizations and individuals responsible for maintaining and updating Apache Tomcat.


Risk Assessment:

Medium risk of Denial-of-Service (DoS) attacks affecting the availability of the Apache Tomcat server when the WebSocket chat example application is deployed.


Impact Assessment:

Potential to consume excessive server resources and impact the availability of the affected application.


Description


Apache Tomcat is an open-source web server and servlet container that runs Java-based web applications.


A vulnerability has been identified in the Apache Tomcat WebSocket chat example application due to uncontrolled resource consumption. The vulnerability exists only in the example web application distributed with Apache Tomcat and does not affect users who have removed the examples web application as recommended by the Apache Tomcat security guidance.


Successful exploitation of this vulnerability could allow an attacker to consume excessive server resources, resulting in a denial-of-service condition that impacts the availability of the affected server.


Solution


Apply appropriate fixes as mentioned in the Apache Tomcat Security Updates:

https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.25



Vendor Information


Apache Tomcat

https://tomcat.apache.org


References


Apache Tomcat

https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.25


CVE Name

CVE-2026-66299




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpssB8ACgkQ3jCgcSdc

ys/SjQ//S1qTWcgZyZ6BtLBoQVwpwsVe4Ht2w+DzGyXvOU60snhh57SeMD3xOCL8

gr4hO2t1UAD5UIGxQg2M2NHAvxRa8ZWFpA9fbL8LOzsSU5dCWCmOTSVhqehzeBr0

iZFfppG9tSu7F4ru3pL8llkLRiaHBwOQ6UgEKoaKOHMLPIMx9fIbjJIwuZ2SCTgF

ynYLZswQzCWUoUJA57dIqO6Leo6ZG0cab7j4FLI7kmm9HSZUlyPySxjxqQsBahqs

X+0ECOO32ZbgE1scxl7btyk8mKo/puzQfrXb2FOXC+7z/w/c7/2NEPWRF4kNZaZJ

YJxUXQXZY5yuACZNmGvRIXYmVgdT0EeNj73Ueft3f6MkkmUo38hFz3qj2CFCYWV/

ZDzwn/l0Gkj6xh53RXSXpJLU4akHP3f7OYqjLSNfwpFx9sLihyfVNU4wmgK1YiUL

XlqGRo9QOd3AX+uowduqRmW1JcLGE0vGNvXuGLTBlX+VqtYlFJMcxpI1qrYPpldB

OYg+C40oj0CZjynwm4FWrLo7ELJoxC8sHFvbSTk+CtKPORPSu9neFnrv/lYvNdWX

oxkLUr2ilkmRn7JvL4OmNcsifIxX7Ugf4CkJLzKMV77GdyKo3VS/pFjgS1kmRwLl

cC8G+j9F2gLxIhPdJZsYLHQJ5a+nF7CMrxveZ2Cku7NXTBvM0qk=

=HmU+

—–END PGP SIGNATURE—–

Share this article