Описание
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117.
Older, unsupported versions may also be affected.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
In Apache Tomcat, no limit was enforced on the request body for WebDAV LOCK or PROPFIND requests which were available to unauthenticated users. This allows a remote attacker to consume excessive resources, leading to Denial of Service (DoS), making the affected system unavailable to legitimate users.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat build of Apache Camel - HawtIO 4 | tomcat-embed-core | Affected | ||
| Red Hat build of Debezium 3 | annotations-api | Will not fix | ||
| Red Hat Data Grid 8 | tomcat-embed-core | Affected | ||
| Red Hat JBoss Web Server 5 | tomcat-embed-core | Affected | ||
| Red Hat Single Sign-On 7 | tomcat-embed-core | Fix deferred | ||
| Red Hat JBoss Web Server 6.2.4 | tomcat-catalina | Fixed | RHSA-2026:43402 | 22.07.2026 |
| Red Hat JBoss Web Server 6.2 on RHEL 10 | jws6-tomcat | Fixed | RHSA-2026:43401 | 22.07.2026 |
| Red Hat JBoss Web Server 6.2 on RHEL 8 | jws6-tomcat | Fixed | RHSA-2026:43401 | 22.07.2026 |
| Red Hat JBoss Web Server 6.2 on RHEL 9 | jws6-tomcat | Fixed | RHSA-2026:43401 | 22.07.2026 |
| Red Hat JBoss Web Server 7.0.0 | tomcat-catalina | Fixed | RHSA-2026:39189 | 14.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
7.5 High
CVSS3
Связанные уязвимости
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117. Older, unsupported versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117. Older, unsupported versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
Allocation of Resources Without Limits or Throttling vulnerability in ...
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
Уязвимость сервера приложений Apache Tomcat, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.5 High
CVSS3