<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 18:37:55 +0000</lastBuildDate>
    <item>
      <title>BIT-tomcat-2026-66299 — Apache Tomcat: DoS via WebSocket chat example</title>
      <link>https://cve.radiocsirt.org/vuln/bit-tomcat-2026-66299</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Tomcat&amp;#39;s WebSocket chat example.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.&lt;/p&gt;
&lt;p&gt;Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: tomcat&lt;/p&gt;
&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Tomcat&amp;#39;s WebSocket chat example.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.&lt;/p&gt;
&lt;p&gt;Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-tomcat-2026-66299</guid>
    </item>
    <item>
      <title>certfr-2026-avi-0940 — Une vulnérabilité a été découverte dans Apache Tomcat. Elle permet à un attaquant de provoquer un déni de service à dis…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0940</link>
      <description>certfr-2026-avi-0940</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0940</guid>
    </item>
    <item>
      <title>EUVD-2026-342164</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-342164</link>
      <description>EUVD-2026-342164</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-342164</guid>
    </item>
    <item>
      <title>fkie_cve-2026-66299</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-66299</link>
      <description>&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Tomcat&amp;#39;s WebSocket chat example.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.&lt;/p&gt;
&lt;p&gt;Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Tomcat&amp;#39;s WebSocket chat example.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.&lt;/p&gt;
&lt;p&gt;Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-66299</guid>
    </item>
    <item>
      <title>GHSA-rpf9-hrjr-88fv</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-rpf9-hrjr-88fv</link>
      <description>&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Tomcat&amp;#39;s WebSocket chat example.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.&lt;/p&gt;
&lt;p&gt;Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Tomcat&amp;#39;s WebSocket chat example.&lt;/p&gt;
&lt;p&gt;This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.&lt;/p&gt;
&lt;p&gt;Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-rpf9-hrjr-88fv</guid>
    </item>
    <item>
      <title>NCSC-2026-0375 — Kwetsbaarheden verholpen in Oracle Communications</title>
      <link>https://cve.radiocsirt.org/vuln/ncsc-2026-0375</link>
      <description>NCSC-2026-0375</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ncsc-2026-0375</guid>
    </item>
    <item>
      <title>OESA-2026-3233 — tomcat security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-3233</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: tomcat, openEuler:24.03-LTS-SP3: tomcat, openEuler:24.03-LTS-SP4: tomcat, openEuler:20.03-LTS-SP4: tomcat, openEuler:22.03-LTS-SP4: tomcat&lt;/p&gt;
&lt;p&gt;Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Tomcat&amp;amp;apos;s WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.(CVE-2026-66299)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP1: tomcat, openEuler:24.03-LTS-SP3: tomcat, openEuler:24.03-LTS-SP4: tomcat, openEuler:20.03-LTS-SP4: tomcat, openEuler:22.03-LTS-SP4: tomcat&lt;/p&gt;
&lt;p&gt;Tomcat is the servlet container that is used in the official Reference Implementation for the Java Servlet and JavaServer Pages technologies. The Java Servlet and JavaServer Pages specifications are developed by Sun under the Java Community Process.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Tomcat&amp;amp;apos;s WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.(CVE-2026-66299)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-3233</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11759-1 — tomcat-9.0.121-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11759-1</link>
      <description>&lt;p&gt;tomcat-9.0.121-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat-9.0.121-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11759-1</guid>
    </item>
    <item>
      <title>RHSA-2026:56039 — Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:56039</link>
      <description>&lt;p&gt;tomcat: Apache Tomcat: Security constraint bypass due to improper access control tomcat: Apache Tomcat: Local information disclosure via Unix domain socket TOCTOU race condition tomcat: Apache Tomcat: Improper Input Validation allows HTTP/2 no-authority bypass of strict SNI validation tomcat: Apache Tomcat: Authentication bypass via limited replay attack in DIGEST authenticator tomcat: Apache Tomcat: Access control bypass due to off-by-one error in RewriteValve [N] flag processing tomcat: Apache Tomcat: Denial of Service via WebSocket chat example tomcat: Apache Tomcat: Improper Authorization allows bypass of declarative role constraints tomcat: Apache Tomcat: Unauthorized resource access via FORM authentication bypass tomcat: Apache Tomcat: Denial of Service via HTTP/2 allocation leak tomcat: Apache Tomcat: Authenticated WebSocket session persists after HTTP session termination&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;tomcat: Apache Tomcat: Security constraint bypass due to improper access control tomcat: Apache Tomcat: Local information disclosure via Unix domain socket TOCTOU race condition tomcat: Apache Tomcat: Improper Input Validation allows HTTP/2 no-authority bypass of strict SNI validation tomcat: Apache Tomcat: Authentication bypass via limited replay attack in DIGEST authenticator tomcat: Apache Tomcat: Access control bypass due to off-by-one error in RewriteValve [N] flag processing tomcat: Apache Tomcat: Denial of Service via WebSocket chat example tomcat: Apache Tomcat: Improper Authorization allows bypass of declarative role constraints tomcat: Apache Tomcat: Unauthorized resource access via FORM authentication bypass tomcat: Apache Tomcat: Denial of Service via HTTP/2 allocation leak tomcat: Apache Tomcat: Authenticated WebSocket session persists after HTTP session termination&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:56039</guid>
    </item>
    <item>
      <title>SUSE-SU-2026:23690-1 — Security update for tomcat10</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2026:23690-1</link>
      <description>&lt;p&gt;Security update for tomcat10&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for tomcat10&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2026:23690-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-66299</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-66299</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: tomcat6, Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:Pro:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9, Ubuntu:Pro:20.04:LTS: tomcat9, Ubuntu:Pro:22.04:LTS: tomcat9, Ubuntu:24.04:LTS: tomcat10, Ubuntu:24.04:LTS: tomcat9 and 3 more&lt;/p&gt;
&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Tomcat&amp;#39;s WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue. Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: tomcat6, Ubuntu:Pro:14.04:LTS: tomcat7, Ubuntu:Pro:16.04:LTS: tomcat8, Ubuntu:Pro:16.04:LTS: tomcat7, Ubuntu:Pro:18.04:LTS: tomcat8, Ubuntu:Pro:18.04:LTS: tomcat9, Ubuntu:Pro:20.04:LTS: tomcat9, Ubuntu:Pro:22.04:LTS: tomcat9, Ubuntu:24.04:LTS: tomcat10, Ubuntu:24.04:LTS: tomcat9 and 3 more&lt;/p&gt;
&lt;p&gt;Uncontrolled Resource Consumption vulnerability in Apache Tomcat&amp;#39;s WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue. Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-66299</guid>
    </item>
    <item>
      <title>WID-SEC-W-2026-2571 — Apache Tomcat: Schwachstelle ermöglicht Denial of Service</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2571</link>
      <description>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Apache Tomcat ausnutzen, um einen Denial of Service Angriff durchzuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2026-2571</guid>
    </item>
  </channel>
</rss>
