Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example
Summary
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue. Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.
What this means
In plain English
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue. Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.
Vulnerable items
- Apache Tomcat — Apache Tomcat is a Java application server and servlet container used to host web applications.
Recommended action
Primary action: update to a vendor-listed fixed release: 11.0.25, 10.1.58, 9.0.121. Vendor mitigation: Users who have followed the security guidance to remove the examples web application are not affected by this issue. Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.
Rewritten locally from the scraped official advisory data above; no generative API is used. The vendor advisory is authoritative.
- 11.0.0-M20 through 11.0.24
- 10.1.24 through 10.1.57
- 9.0.89 through 9.0.120.
- through 9.0.120
Official advisory · medium-confidence parse· fetched 2 hours ago·verify at source
- 11.0.25
- 10.1.58
- 9.0.121
Official advisory · medium-confidence parse· fetched 2 hours ago·verify at source
Mitigation checklist
- Users who have followed the security guidance to remove the examples web application are not affected by this issue.
- Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.
Official advisory · medium-confidence parse· fetched 2 hours ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.