Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-41284

Apache Tomcat: unbounded request body read in WebDAV LOCK and PROPFIND

Technology

Apache Tomcat

CVSS Score

7.5 / 10.0

Affected Versions

11.0.0-M1 to 11.0.21; 10.1.0-M1 to 10.1.54; 9.0.0.M1 to 9.0.117; NVD's configuration also includes 10.0.0 to 10.0.27, 8.5.0 to 8.5.100 and 7.0.109 and earlier

Upstream Fix

11.0.22; 10.1.55; 9.0.118

Published

May 12, 2026

OSSeva Coverage

Fixed upstream

Description

No limit was enforced on the request body for WebDAV LOCK or PROPFIND requests, which unauthenticated users could send, so a client could make Tomcat read an arbitrarily large body. Rated Low by the Tomcat security team; CISA-ADP scores it 7.5. It applies where the WebDAV servlet is enabled. Fixed in 11.0.22, 10.1.55 and 9.0.118.

Upstream record: NVD · CVE.org

Is your Apache Tomcat deployment affected?

If you're running 11.0.0-M1 to 11.0.21; 10.1.0-M1 to 10.1.54; 9.0.0.M1 to 9.0.117; NVD's configuration also includes 10.0.0 to 10.0.27, 8.5.0 to 8.5.100 and 7.0.109 and earlier, you need this patch. Book a discovery call to get covered.