
Ubuntu reported that Apache Tomcat before 9.0.118 is affected by CVE-2026-41284 and CVE-2026-41293, enabling remote attackers to exhaust memory with WebDAV requests and crash or take over servers via crafted HTTP/2 headers. https://threatcluster.io/cluster/multiple-vulnerabilities-discovered-in-tomcat-affecting-webd-380958fe
Post summary
Ubuntu reported that older Apache Tomcat versions (<9.0.118) are vulnerable to CVE‑2026‑41284 and CVE‑2026‑41293, which allow remote attackers to exhaust memory with WebDAV requests and potentially crash or take over servers using crafted HTTP/2 headers.

