CVE-2026-41284

EUVD-2026-29513
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117.
Older, unsupported versions may also be affected.

Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
Affected Products (NVD)
VendorProductVersion
apachetomcat
4.0.0 ≤
𝑥
≤ 7.0.109
apachetomcat
8.5.0 ≤
𝑥
≤ 8.5.100
apachetomcat
9.0.0 ≤
𝑥
< 9.0.118
apachetomcat
10.0.0 ≤
𝑥
≤ 10.0.27
apachetomcat
10.1.0 ≤
𝑥
< 10.1.55
apachetomcat
11.0.0 ≤
𝑥
< 11.0.22
𝑥
= Vulnerable software versions
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
tomcat10
suse enterprise sap 15 SP5
10.1.55-150200.5.67.1
fixed
suse enterprise sap 15 SP6
10.1.55-150200.5.67.1
fixed
suse enterprise sap 15 SP7
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP5
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP6
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP7
10.1.55-150200.5.67.1
fixed
tomcat10-admin-webapps
suse enterprise sap 15 SP5
10.1.55-150200.5.67.1
fixed
suse enterprise sap 15 SP6
10.1.55-150200.5.67.1
fixed
suse enterprise sap 15 SP7
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP5
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP6
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP7
10.1.55-150200.5.67.1
fixed
tomcat10-el-5_0-api
suse enterprise sap 15 SP5
10.1.55-150200.5.67.1
fixed
suse enterprise sap 15 SP6
10.1.55-150200.5.67.1
fixed
suse enterprise sap 15 SP7
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP5
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP6
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP7
10.1.55-150200.5.67.1
fixed
tomcat10-jsp-3_1-api
suse enterprise sap 15 SP5
10.1.55-150200.5.67.1
fixed
suse enterprise sap 15 SP6
10.1.55-150200.5.67.1
fixed
suse enterprise sap 15 SP7
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP5
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP6
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP7
10.1.55-150200.5.67.1
fixed
tomcat10-lib
suse enterprise sap 15 SP5
10.1.55-150200.5.67.1
fixed
suse enterprise sap 15 SP6
10.1.55-150200.5.67.1
fixed
suse enterprise sap 15 SP7
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP5
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP6
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP7
10.1.55-150200.5.67.1
fixed
tomcat10-servlet-6_0-api
suse enterprise sap 15 SP5
10.1.55-150200.5.67.1
fixed
suse enterprise sap 15 SP6
10.1.55-150200.5.67.1
fixed
suse enterprise sap 15 SP7
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP5
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP6
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP7
10.1.55-150200.5.67.1
fixed
tomcat10-webapps
suse enterprise sap 15 SP5
10.1.55-150200.5.67.1
fixed
suse enterprise sap 15 SP6
10.1.55-150200.5.67.1
fixed
suse enterprise sap 15 SP7
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP5
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP6
10.1.55-150200.5.67.1
fixed
suse enterprise server 15 SP7
10.1.55-150200.5.67.1
fixed
tomcat11
suse enterprise sap 15 SP6
11.0.22-150600.13.21.1
fixed
suse enterprise sap 15 SP7
11.0.22-150600.13.21.1
fixed
suse enterprise server 15 SP6
11.0.22-150600.13.21.1
fixed
suse enterprise server 15 SP7
11.0.22-150600.13.21.1
fixed
tomcat11-admin-webapps
suse enterprise sap 15 SP6
11.0.22-150600.13.21.1
fixed
suse enterprise sap 15 SP7
11.0.22-150600.13.21.1
fixed
suse enterprise server 15 SP6
11.0.22-150600.13.21.1
fixed
suse enterprise server 15 SP7
11.0.22-150600.13.21.1
fixed
tomcat11-el-6_0-api
suse enterprise sap 15 SP6
11.0.22-150600.13.21.1
fixed
suse enterprise sap 15 SP7
11.0.22-150600.13.21.1
fixed
suse enterprise server 15 SP6
11.0.22-150600.13.21.1
fixed
suse enterprise server 15 SP7
11.0.22-150600.13.21.1
fixed
tomcat11-jsp-4_0-api
suse enterprise sap 15 SP6
11.0.22-150600.13.21.1
fixed
suse enterprise sap 15 SP7
11.0.22-150600.13.21.1
fixed
suse enterprise server 15 SP6
11.0.22-150600.13.21.1
fixed
suse enterprise server 15 SP7
11.0.22-150600.13.21.1
fixed
tomcat11-lib
suse enterprise sap 15 SP6
11.0.22-150600.13.21.1
fixed
suse enterprise sap 15 SP7
11.0.22-150600.13.21.1
fixed
suse enterprise server 15 SP6
11.0.22-150600.13.21.1
fixed
suse enterprise server 15 SP7
11.0.22-150600.13.21.1
fixed
tomcat11-servlet-6_1-api
suse enterprise sap 15 SP6
11.0.22-150600.13.21.1
fixed
suse enterprise sap 15 SP7
11.0.22-150600.13.21.1
fixed
suse enterprise server 15 SP6
11.0.22-150600.13.21.1
fixed
suse enterprise server 15 SP7
11.0.22-150600.13.21.1
fixed
tomcat11-webapps
suse enterprise sap 15 SP6
11.0.22-150600.13.21.1
fixed
suse enterprise sap 15 SP7
11.0.22-150600.13.21.1
fixed
suse enterprise server 15 SP6
11.0.22-150600.13.21.1
fixed
suse enterprise server 15 SP7
11.0.22-150600.13.21.1
fixed
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
tomcat10
Amazon Linux 2023
1:10.1.55-1.amzn2023.0.1
fixed
tomcat10-admin-webapps
Amazon Linux 2023
1:10.1.55-1.amzn2023.0.1
fixed
tomcat10-docs-webapp
Amazon Linux 2023
1:10.1.55-1.amzn2023.0.1
fixed
tomcat10-el-5.0-api
Amazon Linux 2023
1:10.1.55-1.amzn2023.0.1
fixed
tomcat10-jsp-3.1-api
Amazon Linux 2023
1:10.1.55-1.amzn2023.0.1
fixed
tomcat10-lib
Amazon Linux 2023
1:10.1.55-1.amzn2023.0.1
fixed
tomcat10-servlet-6.0-api
Amazon Linux 2023
1:10.1.55-1.amzn2023.0.1
fixed
tomcat10-webapps
Amazon Linux 2023
1:10.1.55-1.amzn2023.0.1
fixed
tomcat9
Amazon Linux 2023
1:9.0.118-1.amzn2023.0.1
fixed
tomcat9-admin-webapps
Amazon Linux 2023
1:9.0.118-1.amzn2023.0.1
fixed
tomcat9-docs-webapp
Amazon Linux 2023
1:9.0.118-1.amzn2023.0.1
fixed
tomcat9-el-3.0-api
Amazon Linux 2023
1:9.0.118-1.amzn2023.0.1
fixed
tomcat9-jsp-2.3-api
Amazon Linux 2023
1:9.0.118-1.amzn2023.0.1
fixed
tomcat9-lib
Amazon Linux 2023
1:9.0.118-1.amzn2023.0.1
fixed
tomcat9-servlet-4.0-api
Amazon Linux 2023
1:9.0.118-1.amzn2023.0.1
fixed
tomcat9-webapps
Amazon Linux 2023
1:9.0.118-1.amzn2023.0.1
fixed