CVE-2026-68763: CWE-400 Uncontrolled Resource Consumption in Apache Software Foundation Apache Tomcat
Description
An uncontrolled resource consumption vulnerability exists in Apache Tomcat due to an allocation leak in HTTP/2 backlog tracking when a stream is reset. This affects multiple versions across the 8.5.x, 9.0.x, 10.1.x, and 11.0.x branches. The vulnerability can lead to denial of service by exhausting server resources. Fixed versions have been released to address this issue.
CVSS v3.1
Score 7.5high
Affected software
Apache Software Foundation
Apache Tomcat
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-68763 is a CWE-400 uncontrolled resource consumption vulnerability in Apache Tomcat. It arises from an allocation leak in the HTTP/2 backlog tracking mechanism when a stream is reset, causing excessive resource usage. Affected versions include 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.39 through 9.0.120, and 8.5.59 through 8.5.100 (EOL). The issue is resolved in versions 11.0.25, 10.1.58, and 9.0.121.
Potential Impact
The vulnerability allows an attacker to cause a denial of service by exhausting server resources due to an allocation leak in HTTP/2 backlog tracking. There is no impact on confidentiality or integrity. The CVSS v3.1 score is 7.5 (high), reflecting network attack vector, low complexity, no privileges required, no user interaction, and impact limited to availability.
Mitigation Recommendations
Users should upgrade affected Apache Tomcat versions to 11.0.25, 10.1.58, or 9.0.121 or later, where the issue is fixed. No other mitigation or workaround is indicated. Patch status is confirmed by the vendor advisory recommending these upgrades.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- apache
- Date Reserved
- 2026-07-31T15:42:11.281Z
- State
- PUBLISHED
Threat ID: 6a8e15bfacd9273b49c852b4
Added to database: 08/25/2026, 22:22:55 UTC
Last enriched: 09/09/2026, 20:37:32 UTC
Last updated: 10/09/2026, 06:48:18 UTC
Views: 64
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.