Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS attack. This issue affects Apache Tomcat: from 11.0.0-M5 through 11.0.25, from 10.1.8 through 10.1.59, from 9.0.74 through 9.0.121. The fol
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Apache Software Foundation | Apache Tomcat | 11.0.0-M5 ~ 11.0.25 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-31377 | 7.5 HIGH | Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service |
| CVE-2026-75973 | Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured | |
| CVE-2026-82331 | Apache BuildStream: tar source extraction escape | |
| CVE-2026-73192 | Apache Sling XSS: XSS possible through XSSAPI.getValidHref() | |
| CVE-2026-92001 | Apache Sling XSS: Missing parser resource limits | |
| CVE-2026-91999 | Apache Sling XSS: Improper escaping in the XSS Webconsole plugin | |
| CVE-2026-91852 | Apache Sling XSS: CWE-79 multiple raw-string break-outs and ReDOS in XSSImpl | |
| CVE-2026-96443 | Apache Doris: JDBC driver URL validation bypass leads to remote code execution | |
| CVE-2026-91928 | Apache Sling XSS: Sanitizer bypass, uncontrolled resource consumption and failure pf prote | |
| CVE-2026-94251 | Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape | |
| CVE-2026-94243 | Apache Sling Security Bundle: RefererFilter accepts weaker-than-origin evidence | |
| CVE-2026-73581 | Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate us | |
| CVE-2026-86247 | Apache Tomcat Native: Client certificate requirements can be down-graded | |
| CVE-2026-76183 | Apache Tomcat: Bypass of security constraints for WebSocket endpoints | |
| CVE-2026-77756 | Apache Tomcat: Transfer-Encoding honored for HTTP/1.0 requests | |
| CVE-2026-77762 | Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request | |
| CVE-2026-78383 | Apache Tomcat: AJP DoS via missing request body | |
| CVE-2026-78437 | Apache Tomcat: HTTP/2 DoS via malformed request | |
| CVE-2026-79677 | Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout | |
| CVE-2026-86248 | Apache Tomcat: Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with |
Showing top 20 of 25 CVEs. View all on vendor page → →
No comments yet