Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 Maven

Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling

GHSA-gx5v-xp9w-j4cg · BIT-tomcat-2026-41284 · CVE-2026-41284

Published · Modified

Description

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.21
Apache Tomcat 10.1.0-M1 to 10.1.54
Apache Tomcat 9.0.0.M1 to 9.0.117
Older, unsupported versions may also be affected

Description:
No limit was enforced on the request body for WebDAV LOCK or PROPFIND
requests which were available to unauthenticated users.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:

  • Upgrade to Apache Tomcat 11.0.22 or later
  • Upgrade to Apache Tomcat 10.1.55 or later
  • Upgrade to Apache Tomcat 9.0.118 or later

Credit:
This issue was identified by Dariusz Gońda

Ready to move

Start Securing

Free, no credit card | First findings in minutes