PT-2026-40068 · Apache+4 · Apache Tomcat+4

·

CVE-2026-41284

·

Published

2026-05-11

·

Updated

2026-09-11

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 11.0.0-M1 through 11.0.21 Apache Tomcat versions 10.1.0-M1 through 10.1.54 Apache Tomcat versions 9.0.0.M1 through 9.0.117
Description An issue exists involving the allocation of resources without limits or throttling.
Recommendations Upgrade to the fixed version for the affected versions of Apache Tomcat.

Exploit

Fix

DoS

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08084
BIT-TOMCAT-2026-41284
CLEANSTART-2026-NW12954
CVE-2026-41284
GHSA-GX5V-XP9W-J4CG
OESA-2026-2296
OPENSUSE-SU-2026:10925-1
OPENSUSE-SU-2026:10926-1
OPENSUSE-SU-2026:10927-1
OPENSUSE-SU-2026:21117-1
OPENSUSE-SU-2026:21121-1
OPENSUSE-SU-2026:21122-1
RHSA-2026:43401
SUSE-SU-2026:22195-1
SUSE-SU-2026:22196-1
SUSE-SU-2026:22197-1
SUSE-SU-2026:2299-1
SUSE-SU-2026:2374-1
SUSE-SU-2026:2377-1
SUSE-SU-2026:2675-1
USN-8417-1
USN-8450-1

Affected Products

Apache Tomcat
Confluence
Linuxmint
Red Os
Ubuntu