CVE-2026-68763: Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset
Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120.
The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.0.25 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.1.58 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 9.0.121 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 8.5.59
Event History
Frequently Asked Questions
Which Tomcat versions require remediation?
Affected supported release lines are 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, and 9.0.39 through 9.0.120. Upgrade to 11.0.25, 10.1.58, or 9.0.121, respectively; the EOL 8.5.59 through 8.5.100 range is also known to be affected.
What is the impact of exploitation?
The issue is an uncontrolled resource consumption vulnerability caused by an allocation leak in HTTP/2 backlog tracking when a stream is reset. This can result in denial of service.
Are unsupported Tomcat releases relevant?
Yes. Versions 8.5.59 through 8.5.100 were EOL when the CVE was created and are known to be affected, and other unsupported versions may also be affected. Unsupported deployments should be moved to a supported fixed release.