Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3743 articles · 197652 vulns · 37/41 feeds (7d)
← Back to list
7.5
CVE-2026-41284EXPLOITEDPATCHED
apache · tomcat

Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling

Description

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117. Older, unsupported versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

Affected Products

VendorProductVersions
apachetomcatmaven/org.apache.tomcat.embed:tomcat-embed-core: < 9.0.118, maven/org.apache.tomcat.embed:tomcat-embed-core: >= 10.1.0-M1, < 10.1.55, maven/org.apache.tomcat.embed:tomcat-embed-core: >= 11.0.0-M1, < 11.0.22, maven/org.apache.tomcat:tomcat: < 9.0.118, maven/org.apache.tomcat:tomcat: >= 10.1.0-M1, < 10.1.55, maven/org.apache.tomcat:tomcat: >= 11.0.0-M1, < 11.0.22, maven/org.apache.tomcat:tomcat-catalina: < 9.0.118, maven/org.apache.tomcat:tomcat-catalina: >= 10.1.0-M1, < 10.1.55, maven/org.apache.tomcat:tomcat-catalina: >= 11.0.0-M1, < 11.0.22

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
atlassianbamboocert_advisory90%
atlassianfisheyecert_advisory90%
atlassianbitbucketcert_advisory90%
atlassiancruciblecert_advisory90%
atlassianjiracert_advisory90%

References

  • https://lists.apache.org/thread/2nvqjr7ovjmvx2vbhb7s61ycd5msc8qc(vendor-advisory)

Related News (8 articles)

Tier B
BSI Advisories7d ago
[NEU] [hoch] Atlassian Produkte (Bamboo, Bitbucket, Confluence, Crucible, Fisheye, und Jira): Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR19d ago
Multiples vulnérabilités dans les produits IBM (07 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories35d ago
[NEU] [hoch] Oracle Solaris Drittanbieterkomponenten: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR69d ago
Multiples vulnérabilités dans les produits Atlassian (18 juin 2026)
→ No new info (linked only)
Tier B
BSI Advisories70d ago
[NEU] [hoch] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR105d ago
Multiples vulnérabilités dans Apache Tomcat (13 mai 2026)
→ No new info (linked only)
Tier C
VulDB105d ago
CVE-2026-41284 | Apache Tomcat up to 11.0.21 allocation of resources
→ No new info (linked only)
Tier C
oss-security105d ago
CVE-2026-41284: Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
→ No new info (linked only)
CVSS 3.17.5 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
org.apache.tomcat.embed:tomcat-embed-core@9.0.118org.apache.tomcat.embed:tomcat-embed-core@10.1.55org.apache.tomcat.embed:tomcat-embed-core@11.0.22org.apache.tomcat:tomcat@9.0.118org.apache.tomcat:tomcat@10.1.55org.apache.tomcat:tomcat@11.0.22org.apache.tomcat:tomcat-catalina@9.0.118org.apache.tomcat:tomcat-catalina@10.1.55org.apache.tomcat:tomcat-catalina@11.0.22
CWECWE-770
PublishedMay 12, 2026
Last enriched105d agov3
Trending Score26
Source articles8
Independent4
Info Completeness9/14
Missing: cvss, epss, kev, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-44416
Apache Ranger: Remote Code Execution via Arbitrary Class Instantiation
Trending: 42
NONECVE-2026-53434EXP
Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector
Trending: 34
HIGHCVE-2026-57819
Apache CXF: No default restriction on the amount of form parameters per message
Trending: 31
HIGHCVE-2026-54225
Apache CXF: Denial of Service attack via large attachments
Trending: 31
HIGHCVE-2026-64958
Apache CXF: Denial of service via message header attachments
Trending: 31

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 12, 2026
Discovered by ZDM
May 12, 2026
Updated: severity, affectedVersions, exploitAvailable, activelyExploited
May 12, 2026
Updated: description, severity
May 12, 2026
Actively Exploited
May 13, 2026
Exploit Available
May 13, 2026
Patch Available
May 13, 2026

Version History

v3
Last enriched 105d ago
v3Tier C105d ago

Updated description with new details, changed severity to MEDIUM, and noted that no exploit exists.

descriptionseverity
via VulDB
v2Tier C105d ago

Updated severity to LOW, added new affected versions, and marked exploit availability and active exploitation status as true.

severityaffectedVersionsexploitAvailableactivelyExploited
via oss-security
v1105d ago

Initial creation