boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2026-66299

Apache Tomcat: DoS via WebSocket chat example
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   N   L   N   N  U  N  N  L    5.3   .0055   44.2     —
AFFECTED
  Product        Versions      Fixed
  Apache Tomcat  11.0.0-M20 –  —
TIMELINE
  Jul 24  Reserved by apache
  Jul 28  Published (CNA: apache)
  Aug 27  RESCORED — CVE-2026-66299 (Apache Software Foundation Apache Tomcat). CVSS 7.5 → 5.3 (NVD).
CWE-400 · CNA: apache · CVSS v3.1 · 2 references · NVD status: Analyzed

Description

Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue. Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
July 24, 2026ReservedReserved by apache
July 28, 2026PublishedPublished (CNA: apache)
August 27, 2026RESCOREDRESCORED — CVE-2026-66299 (Apache Software Foundation Apache Tomcat). CVSS 7.5 → 5.3 (NVD).

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
Apache Software FoundationApache Tomcat—11.0.0-M20—

Weaknesses

CWE-400

References (2)

Related

Authoritative record: CVE-2026-66299 at cve.org

Vendors: apache

Weaknesses: CWE-400

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-66299 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.