Description
Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail.



This issue affects Apache Tomcat: from 11.0.19 through 11.0.25, from 10.1.53 through 10.1.59, from 9.0.116 through 9.0.121.



Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Published: 2026-09-23
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability comes from incomplete cleanup of state after handling a malformed HTTP/2 request. This flaw can cause a subsequent request from another user to fail, potentially leading to a denial‑of‑service condition for legitimate traffic. It is an improper cleanup weakness (CWE‑459). No information indicates privilege escalation or code execution; the impact is limited to availability.

Affected Systems

Apache Software Foundation’s Apache Tomcat is affected, specifically versions 9.0.116 through 9.0.121, 10.1.53 through 10.1.59, and 11.0.19 through 11.0.25.

Risk and Exploitability

The CVSS score is not provided, and the EPSS score is unavailable, so the exploitation probability is unclear. The CVE is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is a remote attacker sending a malformed HTTP/2 request to the Tomcat server; if successful, it could disrupt service for other users but would require the attacker to reach the application layer. The potential severity is a denial of service that could affect availability. While the EPSS is unknown, the lack of prior exploitation data suggests the risk is moderate, and a patch is recommended.

Generated by OpenCVE AI on September 23, 2026 at 13:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Tomcat to the latest released versions (11.0.26, 10.1.60, or 9.0.122) to apply the fix.
  • If an upgrade is not immediately possible, disable or limit HTTP/2 support for the vulnerable installation to prevent malformed requests from reaching the server.
  • Deploy rate limiting or a web application firewall that blocks malformed HTTP/2 requests and monitor logs for signs of exploitation attempts.

Generated by OpenCVE AI on September 23, 2026 at 13:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 14:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apache Tomcat
Vendors & Products Apache
Apache apache Tomcat

Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail. This issue affects Apache Tomcat: from 11.0.19 through 11.0.25, from 10.1.53 through 10.1.59, from 9.0.116 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.
Title Apache Tomcat: HTTP/2 DoS via malformed request
Weaknesses CWE-459
References

Subscriptions

Apache Apache Tomcat
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-23T16:25:54.815Z

Reserved: 2026-08-24T16:10:49.885Z

Link: CVE-2026-78437

cve-icon Vulnrichment

Updated: 2026-09-23T16:25:28.259Z

cve-icon NVD

Status : Received

Published: 2026-09-23T12:17:07.340

Modified: 2026-09-23T17:17:17.023

Link: CVE-2026-78437

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T13:45:04Z

Weaknesses