GHSA-gx5v-xp9w-j4cgHighCVSS 7.5

Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling

Published
May 12, 2026
Last Modified
May 18, 2026

🔗 CVE IDs covered (1)

📋 Description

Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.21 Apache Tomcat 10.1.0-M1 to 10.1.54 Apache Tomcat 9.0.0.M1 to 9.0.117 Older, unsupported versions may also be affected Description: No limit was enforced on the request body for WebDAV LOCK or PROPFIND requests which were available to unauthenticated users. Mitigation: Users of the affected versions should apply one of the following mitigations: - Upgrade to Apache Tomcat 11.0.22 or later - Upgrade to Apache Tomcat 10.1.55 or later - Upgrade to Apache Tomcat 9.0.118 or later Credit: This issue was identified by Dariusz Gońda

🎯 Affected products9

  • maven/org.apache.tomcat.embed:tomcat-embed-core:< 9.0.118
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 10.1.0-M1, < 10.1.55
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 11.0.0-M1, < 11.0.22
  • maven/org.apache.tomcat:tomcat:< 9.0.118
  • maven/org.apache.tomcat:tomcat:>= 10.1.0-M1, < 10.1.55
  • maven/org.apache.tomcat:tomcat:>= 11.0.0-M1, < 11.0.22
  • maven/org.apache.tomcat:tomcat-catalina:< 9.0.118
  • maven/org.apache.tomcat:tomcat-catalina:>= 10.1.0-M1, < 10.1.55
  • maven/org.apache.tomcat:tomcat-catalina:>= 11.0.0-M1, < 11.0.22

🔗 References (10)