Junglewise Threat Intelligence

CVE-2026-79677: Apache Tomcat WebSocket denial of service due to lost async write timeout

CVE-2026-79677 · Severity: high · CVSS 7.5 · Published 2026-09-23

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat, a widely-used application server that runs Java web applications, has a vulnerability affecting WebSocket connections. An attacker can trigger a denial of service by causing the server to lose track of timeouts on asynchronous WebSocket write operations, allowing malicious writes to accumulate and exhaust server resources.

Technical details

A missing resource cleanup and comparison using incorrect factors in Tomcat's WebSocket handling allows asynchronous write timeouts to be lost, leading to unbounded resource consumption. The vulnerability affects multiple supported and unsupported versions across the 7.x, 8.x, 9.x, 10.x, and 11.x branches. The attack can be triggered over the network via WebSocket connections without authentication or special preconditions.

Affected products

  • Apache Tomcat 11.0.0-M1 through 11.0.25, 10.1.0-M1 through 10.1.59, 9.0.0.M1 through 9.0.121, 8.5.0 through 8.5.100, 7.0.43 through 7.0.109

Timeline

  • 2026-09-23: disclosed

References

Related threats