THREAT OPS › Threat News › CVE-2026-68763: Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset
CVE-2026-68763: Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset
<p>Posted by Mark Thomas on Aug 25</p>Severity: important<br /> <br /> Affected versions:<br /> <br /> - Apache Tomcat 11.0.0-M1 through 11.0.24<br /> - Apache Tomcat 10.1.0-M1 through 10.1.57<br /> - Apache Tomcat 9.0.39 through 9.0.120<br /> - Apache Tomcat 8.5.59 through 8.5.100<br /> - Apache Tomcat through 7.0.109 unaffected<br /> <br /> Description:<br /> <br /> Uncontrolled Resource Consump
Indicators of compromise
- CVE-2026-68763cve
Original source: https://seclists.org/oss-sec/2026/q3/587