Executive brief
Apache Tomcat, a widely-used application server that runs Java web applications, has a vulnerability affecting WebSocket connections. An attacker can trigger a denial of service by causing the server to lose track of timeouts on asynchronous WebSocket write operations, allowing malicious writes to accumulate and exhaust server resources.
Technical details
A missing resource cleanup and comparison using incorrect factors in Tomcat's WebSocket handling allows asynchronous write timeouts to be lost, leading to unbounded resource consumption. The vulnerability affects multiple supported and unsupported versions across the 7.x, 8.x, 9.x, 10.x, and 11.x branches. The attack can be triggered over the network via WebSocket connections without authentication or special preconditions.
Affected products
- Apache Tomcat 11.0.0-M1 through 11.0.25, 10.1.0-M1 through 10.1.59, 9.0.0.M1 through 9.0.121, 8.5.0 through 8.5.100, 7.0.43 through 7.0.109
Timeline
- 2026-09-23: disclosed