
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-66299 is an Uncontrolled Resource Consumption (DoS) vulnerability in Apache Tomcat's WebSocket chat example application. It affects Apache Tomcat versions 11.0.0-M20 through 11.0.24, 10.1.24 through 10.1.57, and 9.0.89 through 9.0.120; Apache Tomcat 8.5.x and earlier are unaffected. The vulnerability was disclosed on July 28, 2026, by researchers 4ra1n, pyn3rd, and unam4, and patched in versions 11.0.25, 10.1.58, and 9.0.121 (Apache Advisory, Openwall OSS-Sec). It carries a CVSS v3.1 base score of 7.5 (High) (GitHub Advisory).
The vulnerability is classified as CWE-400 (Uncontrolled Resource Consumption) and resides specifically in the WebSocket chat example bundled with Apache Tomcat's examples web application (GitHub Advisory). An unauthenticated remote attacker can exploit this flaw by sending crafted WebSocket messages to the chat example endpoint, causing the server to consume excessive resources without proper throttling or limits. No authentication or user interaction is required, and the attack complexity is low, making it straightforward to automate (Apache Advisory). The vulnerability is only present when the examples web application is deployed — installations that have already removed it per Apache's standard security hardening guidance are not affected (Openwall OSS-Sec).
Successful exploitation results in a denial-of-service condition, exhausting server resources and rendering the Apache Tomcat instance unavailable to legitimate users. There is no impact on confidentiality or data integrity — the vulnerability is limited to availability (GitHub Advisory). The scope is unchanged, meaning the impact is confined to the vulnerable Tomcat instance itself without direct lateral movement potential (Apache Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Apache Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.31–0.45%, placing it in the lower percentiles for near-term exploitation likelihood (GitHub Advisory). The attack is automatable due to the lack of authentication and low complexity requirements, but exploitation is limited to deployments that retain the examples web application.
/examples/ on the target./examples/websocket/chat.xhtml or a similar path on the target Tomcat server.websockets library, wscat) to open a large number of concurrent WebSocket connections to the chat endpoint./examples/websocket/ endpoints; sustained high-bandwidth traffic from one or more source IPs targeting the Tomcat examples application.HTTP 101 Switching Protocols) to the chat example endpoint from the same or rotating source IPs; Java out-of-memory errors or thread pool exhaustion messages in catalina.out.The primary remediation is to upgrade Apache Tomcat to a fixed version: 11.0.25, 10.1.58, or 9.0.121 (or later) (Apache Advisory). As an immediate workaround — and as a general security best practice — remove the examples web application from all production Tomcat deployments; installations without the examples application are not affected by this vulnerability (Openwall OSS-Sec). Network-level controls such as rate limiting WebSocket connections or blocking access to /examples/ via a reverse proxy or firewall can also reduce exposure until patching is complete.
The Apache Tomcat security team rated this vulnerability as low severity in their official disclosure, reflecting the limited scope (examples application only) and lack of confidentiality or integrity impact (Openwall OSS-Sec). The vulnerability was credited to researchers 4ra1n, pyn3rd, and unam4. Community reaction has been measured, with standard coverage from vulnerability aggregators and scanner vendors (Tenable Nessus, Qualys) adding detection plugins shortly after disclosure (Apache Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."