🔐 CVE Alert

CVE-2026-41284

HIGH 7.5

Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
5th

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117. Older, unsupported versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

CWE CWE-770
Vendor apache software foundation
Product apache tomcat
Published May 12, 2026
Last Updated May 13, 2026
Stay Ahead of the Next One

Get instant alerts for apache software foundation apache tomcat

Be the first to know when new high vulnerabilities affecting apache software foundation apache tomcat are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

Apache Software Foundation / Apache Tomcat
11.0.0-M1 ≤ 11.0.21 10.1.0-M1 ≤ 10.1.54 9.0.0.M1 ≤ 9.0.117 10.0.0-M1 ≤ 10.0.27 8.5.0 ≤ 8.5.100 4.0 ≤ 7.0.109

References

NVD ↗ CVE.org ↗ EPSS Data ↗
lists.apache.org: https://lists.apache.org/thread/2nvqjr7ovjmvx2vbhb7s61ycd5msc8qc openwall.com: http://www.openwall.com/lists/oss-security/2026/05/12/12

Credits

Dariusz Gońda