CVE-2026-77791: Apache Tomcat: DoS via busy wait during WebSocket close
Apache Tomcat WebSocket close handling can busy-wait, enabling denial of service across multiple supported versions.
Apache disclosed CVE-2026-77791, an important uncontrolled resource consumption bug in Tomcat. Sending a WebSocket close message can enter a busy wait and enable denial of service. Affected ranges are 11.0.0-M5 through 11.0.25, 10.1.8 through 10.1.59, 9.0.74 through 9.0.121, 8.5.88 through 8.5.100, and Tomcat through 7.0.109. The advisory does not report active exploitation.
- CVE-2026-77791 is an uncontrolled resource consumption flaw in Apache Tomcat.
- A busy wait while sending a WebSocket close message can cause denial of service.
- Affects 11.0.0-M5–11.0.25, 10.1.8–10.1.59, 9.0.74–9.0.121, 8.5.88–8.5.100, and through 7.0.109.
- Apache rates the issue important; the notice does not report exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-777917.5—Denial of Service in Apache Tomcat WebSocket Close Message Handlingpublished · Apache Tomcat
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-77791 | Denial of Service in Apache Tomcat WebSocket Close Message Handling Apache Tomcat contains an uncontrolled resource consumption flaw (CWE-400) that is triggered while the server is sending a WebSocket close message, allowing a remote, unauthenticated attacker to exhaust resources and cause denial of service. The attack requires only the ability to open WebSocket connections to a Tomcat instance that serves WebSocket endpoints, with no privileges or user interaction needed. Successful exploitation degrades or takes down the availability of the affected server (CVSS 3.1: 7.5, AV:N/AC:L/PR:N/UI:N/A:H); confidentiality and integrity are not impacted. All currently supported Tomcat branches are affected within the listed version ranges, plus the end-of-life 8.5.x branch. As of this writing there is no known public proof of concept, the issue is not on the CISA KEV list, and no in-the-wild exploitation has been reported. |
Posted by Mark Thomas on Sep 23 Severity: important Affected versions: - Apache Tomcat 11.0.0-M5 through 11.0.25 - Apache Tomcat 10.1.8 through 10.1.59 - Apache Tomcat 9.0.74 through 9.0.121 - Apache Tomcat 8.5.88 through 8.5.100 - Apache Tomcat through 7.0.109 unaffected Description: Uncontrolled Resource Consumption vulnerability in Apache Tomcat during sending of WebSocket close message enabled a DoS attack. This issue affects Apache Tomcat: from 11.0.0-M5 through...
This source does not provide full text. Read it at seclists.org.