CVE-2026-78383

LOWCVSS 7.5 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP request to pin an AJP processing thread leading to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-09-23: 209-23
Referenced assets2 URLs
Full discourse2 posts
  • Kazuki Omo@omokazuki

    Tomcatの脆弱性(Critical: CVE-2026-76183, CVE-2026-86248, CVE-2026-86350, High: CVE-2026-75973, CVE-2026-77762, CVE-2026-77791, CVE-2026-78383, CVE-2026-78437, CVE-2026-79677, CVE-2026-87022, Medium: CVE-2026-73581, Low: CVE-2026-77756) https://security.sios.jp/vulnerability/tomcat-security-vulnerability-20260924/

    00012124
    372 followersView on X
  • CVE@CVEnew

    CVE-2026-78383 Allocation of resources without limits or throttling vulnerability in Apache Tomcat allows an unauthenticated AJP request to pin an AJP processing thread leading to d… https://www.cve.org/CVERecord?id=CVE-2026-78383

    000001.3K
    58.1K followersView on X

Explore more