Apache · Apache Tomcat · CVE-2026-68763
**Name of the Vulnerable Software and Affected Versions**
Apache Tomcat versions 11.0.0-M1 through 11.0.24
Apache Tomcat versions 10.1.0-M1 through 10.1.57
Apache Tomcat versions 9.0.39 through 9.0.120
Apache Tomcat versions 8.5.59 through 8.5.100
**Description**
An uncontrolled resource consumption issue exists due to an allocation leak in the HTTP/2 backlog tracking that occurs when a stream is reset.
**Recommendations**
Upgrade to version 11.0.25.
Upgrade to version 10.1.58.
Upgrade to version 9.0.121.