Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-41284

Опубликовано: 12 мая 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117. Older, unsupported versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

In Apache Tomcat, no limit was enforced on the request body for WebDAV LOCK or PROPFIND requests which were available to unauthenticated users. This allows a remote attacker to consume excessive resources, leading to Denial of Service (DoS), making the affected system unavailable to legitimate users.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel - HawtIO 4tomcat-embed-coreAffected
Red Hat build of Debezium 3annotations-apiWill not fix
Red Hat Data Grid 8tomcat-embed-coreAffected
Red Hat JBoss Web Server 5tomcat-embed-coreAffected
Red Hat Single Sign-On 7tomcat-embed-coreFix deferred
Red Hat JBoss Web Server 6.2.4tomcat-catalinaFixedRHSA-2026:4340222.07.2026
Red Hat JBoss Web Server 6.2 on RHEL 10jws6-tomcatFixedRHSA-2026:4340122.07.2026
Red Hat JBoss Web Server 6.2 on RHEL 8jws6-tomcatFixedRHSA-2026:4340122.07.2026
Red Hat JBoss Web Server 6.2 on RHEL 9jws6-tomcatFixedRHSA-2026:4340122.07.2026
Red Hat JBoss Web Server 7.0.0tomcat-catalinaFixedRHSA-2026:3918914.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2476518tomcat: Apache Tomcat: Denial of Service due to uncontrolled resource allocation

EPSS

Процентиль: 52%
0.0078
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
3 месяца назад

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117. Older, unsupported versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

CVSS3: 7.5
nvd
3 месяца назад

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117. Older, unsupported versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

CVSS3: 7.5
debian
3 месяца назад

Allocation of Resources Without Limits or Throttling vulnerability in ...

CVSS3: 7.5
github
3 месяца назад

Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling

CVSS3: 7.5
fstec
3 месяца назад

Уязвимость сервера приложений Apache Tomcat, связанная с неограниченным распределением ресурсов, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 52%
0.0078
Низкий

7.5 High

CVSS3