CVE-2026-68763
Last modified
CVE-2026-68763 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | >= 8.5.59, < 9.0.121 |
| Apache | Tomcat | >= 10.1.0, < 10.1.58 |
| Apache | Tomcat | >= 11.0.0, < 11.0.25 |
References
- https://lists.apache.org/thread/tv51ty39ppv41v04hdtkp9dp7tg02nzlVendor Advisory, Mailing List
- https://www.openwall.com/lists/oss-security/2026/08/26/9Third Party Advisory, Mailing List
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-68763?
How severe is CVE-2026-68763?
How do I fix CVE-2026-68763?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-68757A user with access to a valid SAML response may impersonate …7.5
- CVE-2026-68758A low-privileged authenticated user may access restricted su…6.5
- CVE-2026-68759A holder of a valid integration credential may impersonate o…7.2
- CVE-2026-6876ServiceNow has remediated a sandbox escape security issue th…10
- CVE-2026-68760An unauthenticated user may bypass authentication under spec…5.3
- CVE-2026-68762In JetBrains Ktor before 3.4.1 potential DoS attack via WebS…5.9
- CVE-2026-68765hashcat master branch builds after v7.1.2 contain a heap buf…6.1
- CVE-2026-68766hashcat fails to restrict command-line options when parsing …7.8
- CVE-2026-68767hashcat's fgetl() function in src/filehandling.c writes a nu…6.1
- CVE-2026-68768hashcat contains a heap-based buffer overflow (out-of-bounds…6.1
- CVE-2026-68769Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-68770sentence-transformers contains a security control bypass vul…9.8
Are you affected by CVE-2026-68763?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
