Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-66299

Gravedad CVSS v3.1:
ALTA
Tipo:
CWE-400 Consumo de recursos no controlado (Agotamiento de recursos)
Fecha de publicación:
28/07/2026
Última modificación:
05/08/2026

Descripción

*** Pendiente de traducción *** Uncontrolled Resource Consumption vulnerability in Apache Tomcat&amp;#39;s WebSocket chat example.<br /> <br /> This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.<br /> <br /> Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.

Productos y versiones vulnerables

CPE Desde Hasta
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* 9.0.89 (incluyendo) 9.0.121 (excluyendo)
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* 10.1.24 (incluyendo) 10.1.58 (excluyendo)
cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:* 11.0.1 (incluyendo) 11.0.25 (excluyendo)
cpe:2.3:a:apache:tomcat:11.0.0:milestone20:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone21:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone22:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone23:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone24:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone25:*:*:*:*:*:*
cpe:2.3:a:apache:tomcat:11.0.0:milestone26:*:*:*:*:*:*