Intel

AIKIDO-2026-915093

tomcat-embed-core is vulnerable to Denial of Service

Denial of ServiceCVE-2026-68763 Published Today

75

High Risk

This Affects:

JAVAtomcat-embed-core
8.5.59 - 9.0.120
Fixed in 9.0.121
10.1.0 - 10.1.57
Fixed in 10.1.59
11.0.0 - 11.0.24
Fixed in 11.0.25
Are you affected? Scan for Free

TL;DR

tomcat-embed-core leaks allocations in HTTP/2 backlog tracking when a stream is reset. A remote client can reset streams to consume tracking resources. Repeated resets can exhaust the server and deny service. The fix releases backlog tracking state when a stream is reset.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and HTTP/2 is enabled.

Background info

tomcat-embed-core is vulnerable to Denial of Service in versions 8.5.59 - 9.0.120, 10.1.0 - 10.1.57 and 11.0.0 - 11.0.24.

How to fix this

Upgrade the org.apache.tomcat.embed:tomcat-embed-core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform