https://seclists.org/oss-sec/2026/q3/903: CVE-2026-77791: Apache Tomcat: DoS via busy wait during WebSocket close
Published Sep 23, 2026
·Updated
Affected Software
1 affected component
Apache Tomcat>=11.0.0-M5<=11.0.25, >=10.1.8<=10.1.59, >=9.0.74<=9.0.121, >=8.5.88<=8.5.100
Frequently Asked Questions
1
Which Tomcat deployments should be prioritized for review?
Review deployments running Tomcat 11.0.0-M5 through 11.0.25, 10.1.8 through 10.1.59, 9.0.74 through 9.0.121, or 8.5.88 through 8.5.100. Tomcat versions through 7.0.109 are listed as unaffected.