보안뉴스 아카이브
긴급도 10/100 심각도 5.3 · 보통 악용확률 42.9% CWE-400

CVE-2026-66299

Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.

This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.

Users are recommended to remove the examples web application or to upgrade to version 11.0.25, 10.1.58 or 9.0.121 (when released), which fix the issue.
KISA 보호나라 보안공지

Apache 제품 보안 업데이트 권고

Apache 재단은 자사 제품에서 발생하는 취약점을 해결한 보안 업데이트 발표 [1]~[10] o 영향을 받는 버전을 사용 중인 사용자는 해결 방안에 따라 최신 버전으로 업데이트 권고

KISA 원문 ↗

벡터: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

NVD 상세 ↗   벤더 권고문 ↗   참고 링크 ↗

이 취약점을 다룬 기사 (1)

← 취약점 목록