Executive brief
Apache Tomcat is a widely-used web server that handles HTTP requests and WebSocket connections for many business applications. A flaw in how Tomcat closes WebSocket connections allows an attacker to trigger a resource-exhaustion denial of service attack, potentially disrupting access to web applications that rely on WebSocket functionality.
Technical details
An uncontrolled resource consumption vulnerability exists in the WebSocket close message handling code path, enabling a denial of service through busy-wait behavior. The attack is network-accessible and requires no authentication; an attacker can send crafted WebSocket close messages to exhaust CPU or other resources. The vendor has released patched versions to address this issue.
Affected products
- Apache Tomcat 11.0.0-M5 through 11.0.25, 10.1.8 through 10.1.59, 9.0.74 through 9.0.121, 8.5.88 through 8.5.100
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Fixed in Tomcat 11.0.26, 10.1.60, and 9.0.122