Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-68763

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 7.5

Описание

Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

A flaw was found in Apache Tomcat. This vulnerability, an uncontrolled resource consumption issue, arises from an allocation leak in the HTTP/2 backlog tracking when a stream is reset. A remote attacker could exploit this to cause a Denial of Service (DoS), making the server unresponsive or unavailable to users.

Отчет

This Important flaw in Apache Tomcat, as shipped with Red Hat JBoss Web Server, allows a remote, unauthenticated attacker to cause a denial of service. The vulnerability stems from an allocation leak in the HTTP/2 backlog tracking, which can be triggered by resetting an HTTP/2 stream, leading to resource exhaustion and service unavailability.

Меры по смягчению последствий

To mitigate this vulnerability, disable the HTTP/2 protocol in Apache Tomcat if it is not required for your deployment. This can be achieved by commenting out or removing the element within the configuration in the server.xml file. After modifying server.xml, a restart of the Apache Tomcat service is required for the changes to take effect.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tomcatUnder investigation
Red Hat Enterprise Linux 10tomcat9Under investigation
Red Hat Enterprise Linux 6tomcat6Under investigation
Red Hat Enterprise Linux 7tomcatUnder investigation
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineUnder investigation
Red Hat Enterprise Linux 8tomcatUnder investigation
Red Hat Enterprise Linux 9tomcatUnder investigation
Red Hat JBoss Web Server 5tomcatOut of support scope
Red Hat JBoss Web Server 6tomcatAffected
Red Hat JBoss Web Server 7tomcatAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2524166org.apache.tomcat/tomcat: Apache Tomcat: Denial of Service via HTTP/2 allocation leak

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
30 дней назад

Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

CVSS3: 7.5
nvd
30 дней назад

Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

CVSS3: 7.5
debian
30 дней назад

Uncontrolled Resource Consumption vulnerability in Apache Tomcatvia an ...

CVSS3: 7.5
github
30 дней назад

Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

suse-cvrf
8 дней назад

Security update for tomcat

7.5 High

CVSS3