CVE-2026-41284General(apache / tomcat)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117. Older, unsupported versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tomcat

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-05-12); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
tomcat

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-05-12: 1Mentions · 2026-06-10: 1Technical Details · 2026-06-10: 105-1206-10
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-121
General1
2026-06-101
Disclosure1
Full discourse2 posts
  • ThreatCluster@threatcluster
    Disclosure

    Ubuntu reported that Apache Tomcat before 9.0.118 is affected by CVE-2026-41284 and CVE-2026-41293, enabling remote attackers to exhaust memory with WebDAV requests and crash or take over servers via crafted HTTP/2 headers. https://threatcluster.io/cluster/multiple-vulnerabilities-discovered-in-tomcat-affecting-webd-380958fe

    Post summary

    Ubuntu reported that older Apache Tomcat versions (<9.0.118) are vulnerable to CVE‑2026‑41284 and CVE‑2026‑41293, which allow remote attackers to exhaust memory with WebDAV requests and potentially crash or take over servers using crafted HTTP/2 headers.

    0000050
    318 followersView on X
  • Kazuki Omo@omokazuki
    General

    Apache Tomcatの脆弱性(Moderate: CVE-2026-43512, CVE-2026-43515, Low: CVE-2026-41284, CVE-2026-41293, CVE-2026-42498, CVE-2026-43513, CVE-2026-43514) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #tomcat #mod_jk #apache https://security.sios.jp/vulnerability/tomcat-security-vulnerability-20260513/

    Post summary

    The post lists several Apache Tomcat CVEs with their severity levels and provides a link to a vulnerability page, but offers no detailed technical analysis, exploit code, or mitigation information.

    00000222
    371 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat---

Explore more