Description
Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS attack.



This issue affects Apache Tomcat: from 11.0.0-M5 through 11.0.25, from 10.1.8 through 10.1.59, from 9.0.74 through 9.0.121.



The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.88 through 8.5.100. Other unsupported versions may also be affected.




Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Published: 2026-09-23
Score: 7.5 High
EPSS: n/a
KEV: No
Impact: Denial of Service via uncontrolled resource consumption during WebSocket close
Action: Immediate Patch
AI Analysis

Impact

Apache Tomcat processes WebSocket close messages in a manner that can cause the server to enter a busy wait loop, consuming CPU time and memory. This results in a denial of service condition that degrades or stops legitimate traffic, impacting availability of applications that rely on WebSocket endpoints. The vulnerability is a CWE‑400 Uncontrolled Resource Consumption flaw.

Affected Systems

The flaw affects Apache Tomcat versions 11.0.0‑M5 through 11.0.25, 10.1.8 through 10.1.59, and 9.0.74 through 9.0.121. EOL releases from 8.5.88 to 8.5.100 are also known to be affected, and other unsupported releases may be vulnerable.

Risk and Exploitability

A remote attacker who can send WebSocket close frames to an affected Tomcat instance can trigger the busy wait loop and cause service disruption. The CVSS score of 7.5 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in the KEV catalog, so the exact likelihood of use in the wild remains unknown. The impact is a loss of availability for any client relying on the WebSocket endpoint.

Generated by OpenCVE AI on September 23, 2026 at 15:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Tomcat to version 11.0.26, 10.1.60, or 9.0.122 or later, which contain the fix for this DoS condition.
  • Replace any existing older Tomcat installations on all production environments (staging, test, prod) with the updated version, ensuring all servers run a fixed release.
  • Validate that the WebSocket functionality remains operational after the upgrade in a controlled test environment before rolling out to all users.

Generated by OpenCVE AI on September 23, 2026 at 15:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apache Tomcat
Vendors & Products Apache
Apache apache Tomcat

Wed, 23 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS attack. This issue affects Apache Tomcat: from 11.0.0-M5 through 11.0.25, from 10.1.8 through 10.1.59, from 9.0.74 through 9.0.121. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.88 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Title Apache Tomcat: DoS via busy wait during WebSocket close
Weaknesses CWE-400
References

Subscriptions

Apache Apache Tomcat
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-23T12:50:22.374Z

Reserved: 2026-08-21T12:38:02.420Z

Link: CVE-2026-77791

cve-icon Vulnrichment

Updated: 2026-09-23T12:45:13.588Z

cve-icon NVD

Status : Received

Published: 2026-09-23T12:17:06.927

Modified: 2026-09-23T13:17:29.853

Link: CVE-2026-77791

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T15:30:07Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption