CVE-2026-41284
Analyzed
Analyzed - Analysis Complete
BaseFortify
Publication date: 2026-05-12
Last updated on: 2026-05-14
Assigner: Apache Software Foundation
Description
Description
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117.
Older, unsupported versions may also be affected.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| apache | tomcat | From 4.0.0 (inc) to 7.0.109 (inc) |
| apache | tomcat | From 8.5.0 (inc) to 8.5.100 (inc) |
| apache | tomcat | From 9.0.0 (inc) to 9.0.118 (exc) |
| apache | tomcat | From 10.0.0 (inc) to 10.0.27 (inc) |
| apache | tomcat | From 10.1.0 (inc) to 10.1.55 (exc) |
| apache | tomcat | From 11.0.0 (inc) to 11.0.22 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-770 | The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated. |
Attack-Flow Graph
Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70