CVE-2026-68763

Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset

Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.59 through 8.5.100. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.


We have discovered 3,412 live websites that are affected by CVE-2026-68763.

Run a Free Instant Scan




Affected Software

Product  Apache Tomcat
Category Web Servers
Vulnerable Domains3,412 live websites (48% of Apache Tomcat install base)
Vulnerable Versions
  • from 8.5.59 through 8.5.100
  • from 9.0.39 through 9.0.120
  • from 10.1 through 10.1.57
  • from 11 through 11.0.24
Vulnerable Versions Count159 versions ( 42% of all versions)


Common Weakness Enumeration

CWE-400 Uncontrolled Resource Consumption



Details

  • Published - Aug 25, 2026
  • Updated - Aug 26, 2026

Credits

  • Zhen Kong (finder)

Website Distribution by Country

Number of websites using CVE-2026-68763
United States1,311 websites



China471 websites
Germany255 websites
France110 websites
Italy106 websites
Hong Kong76 websites
Brazil71 websites
GB70 websites
Netherlands62 websites

Website Distribution by TLD

Number of websites using CVE-2026-68763
.com1,377 websites
.de187 websites
.edu179 websites
.net145 websites
.org108 websites
.cn104 websites
.it99 websites
.com.br90 websites
.fr48 websites
.cz47 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-68763

Top websites that are affected by CVE-2026-68763. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.edu United States***
**.***.*****.*****.***.com United States**,***
*****.********.com United States**,***
*********.**********.com United States**,***
************.com United States**,***
***.*******.com United States**,***
***.*********.edu United States**,***
******.com China**,***
********.*********.com United States**,***
***.****.edu United States**,***
See full domain list

FAQ

CVE-2026-68763 is Uncontrolled Resource Consumption in Apache Tomcat
A total of 3,412 websites have been identified as vulnerable to CVE-2026-68763, based on global website indexing conducted by WebTechSurvey.
The Apache Tomcat is affected by the CVE-2026-68763 vulnerability.
Apache Tomcat versions up to and including 11.0.24 are vulnerable to CVE-2026-68763.