Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
CVE-2026-66299
Apache Tomcat: DoS via WebSocket chat example
AV AC PR UI S C I A CVSS EPSS %ile KEV
N L N N U N N L 5.3 .0055 44.2 —
AFFECTED
Product Versions Fixed
Apache Tomcat 11.0.0-M20 – —
TIMELINE
Jul 24 Reserved by apache
Jul 28 Published (CNA: apache)
Aug 27 RESCORED — CVE-2026-66299 (Apache Software Foundation Apache Tomcat). CVSS 7.5 → 5.3 (NVD).
Description
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.
This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.
Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.
Lifecycle
Complete event history — 3 events, chronological
| Date | Event | Detail |
| July 24, 2026 | Reserved | Reserved by apache |
| July 28, 2026 | Published | Published (CNA: apache) |
| August 27, 2026 | RESCORED | RESCORED — CVE-2026-66299 (Apache Software Foundation Apache Tomcat). CVSS 7.5 → 5.3 (NVD). |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| Apache Software Foundation | Apache Tomcat | — | 11.0.0-M20 | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-66299 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.