Apache Tomcat HTTP/2 backlog leak exhaustion (<=9.0.120/10.1.57/11.0.24)
CVE-2026-68763 Published on August 25, 2026
Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset
Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Weakness Type
What is a Resource Exhaustion Vulnerability?
The software does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.
CVE-2026-68763 has been classified to as a Resource Exhaustion vulnerability or weakness.
Products Associated with CVE-2026-68763
Want to know whenever a new CVE is published for Apache Tomcat? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Tomcat:- Version 11.0.0-M1, <= 11.0.24 is affected.
- Version 10.1.0-M1, <= 10.1.57 is affected.
- Version 9.0.39, <= 9.0.120 is affected.
- Version 8.5.59, <= 8.5.100 is affected.
- Before and including 7.0.109 is unaffected.