
[CIVN-2026-0382] Apache Tomcat Denial-of-Service (DoS) Vulnerability in WebSocket Chat Example
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Apache Tomcat Denial-of-Service (DoS) Vulnerability in WebSocket Chat Example
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: MEDIUM
Software Affected
Apache Tomcat version 11.0.0-M20 through 11.0.24
Apache Tomcat version 10.1.24 through 10.1.57
Apache Tomcat version 9.0.89 through 9.0.120
Overview
A vulnerability has been reported in Apache Tomcat that could allow an attacker to cause a denial-of-service (DoS) condition by exploiting the WebSocket chat example application.
Target Audience:
All end-user organizations and individuals responsible for maintaining and updating Apache Tomcat.
Risk Assessment:
Medium risk of Denial-of-Service (DoS) attacks affecting the availability of the Apache Tomcat server when the WebSocket chat example application is deployed.
Impact Assessment:
Potential to consume excessive server resources and impact the availability of the affected application.
Description
Apache Tomcat is an open-source web server and servlet container that runs Java-based web applications.
A vulnerability has been identified in the Apache Tomcat WebSocket chat example application due to uncontrolled resource consumption. The vulnerability exists only in the example web application distributed with Apache Tomcat and does not affect users who have removed the examples web application as recommended by the Apache Tomcat security guidance.
Successful exploitation of this vulnerability could allow an attacker to consume excessive server resources, resulting in a denial-of-service condition that impacts the availability of the affected server.
Solution
Apply appropriate fixes as mentioned in the Apache Tomcat Security Updates:
https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.25
Vendor Information
Apache Tomcat
https://tomcat.apache.org
References
Apache Tomcat
https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.25
CVE Name
CVE-2026-66299
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpssB8ACgkQ3jCgcSdc
ys/SjQ//S1qTWcgZyZ6BtLBoQVwpwsVe4Ht2w+DzGyXvOU60snhh57SeMD3xOCL8
gr4hO2t1UAD5UIGxQg2M2NHAvxRa8ZWFpA9fbL8LOzsSU5dCWCmOTSVhqehzeBr0
iZFfppG9tSu7F4ru3pL8llkLRiaHBwOQ6UgEKoaKOHMLPIMx9fIbjJIwuZ2SCTgF
ynYLZswQzCWUoUJA57dIqO6Leo6ZG0cab7j4FLI7kmm9HSZUlyPySxjxqQsBahqs
X+0ECOO32ZbgE1scxl7btyk8mKo/puzQfrXb2FOXC+7z/w/c7/2NEPWRF4kNZaZJ
YJxUXQXZY5yuACZNmGvRIXYmVgdT0EeNj73Ueft3f6MkkmUo38hFz3qj2CFCYWV/
ZDzwn/l0Gkj6xh53RXSXpJLU4akHP3f7OYqjLSNfwpFx9sLihyfVNU4wmgK1YiUL
XlqGRo9QOd3AX+uowduqRmW1JcLGE0vGNvXuGLTBlX+VqtYlFJMcxpI1qrYPpldB
OYg+C40oj0CZjynwm4FWrLo7ELJoxC8sHFvbSTk+CtKPORPSu9neFnrv/lYvNdWX
oxkLUr2ilkmRn7JvL4OmNcsifIxX7Ugf4CkJLzKMV77GdyKo3VS/pFjgS1kmRwLl
cC8G+j9F2gLxIhPdJZsYLHQJ5a+nF7CMrxveZ2Cku7NXTBvM0qk=
=HmU+
—–END PGP SIGNATURE—–


