CVE-2026-41284
Apache Tomcat: unbounded request body read in WebDAV LOCK and PROPFIND
Technology
Apache Tomcat
CVSS Score
7.5 / 10.0
Affected Versions
11.0.0-M1 to 11.0.21; 10.1.0-M1 to 10.1.54; 9.0.0.M1 to 9.0.117; NVD's configuration also includes 10.0.0 to 10.0.27, 8.5.0 to 8.5.100 and 7.0.109 and earlier
Upstream Fix
11.0.22; 10.1.55; 9.0.118
Published
May 12, 2026
OSSeva Coverage
Fixed upstream
Description
No limit was enforced on the request body for WebDAV LOCK or PROPFIND requests, which unauthenticated users could send, so a client could make Tomcat read an arbitrarily large body. Rated Low by the Tomcat security team; CISA-ADP scores it 7.5. It applies where the WebDAV servlet is enabled. Fixed in 11.0.22, 10.1.55 and 9.0.118.
Is your Apache Tomcat deployment affected?
If you're running 11.0.0-M1 to 11.0.21; 10.1.0-M1 to 10.1.54; 9.0.0.M1 to 9.0.117; NVD's configuration also includes 10.0.0 to 10.0.27, 8.5.0 to 8.5.100 and 7.0.109 and earlier, you need this patch. Book a discovery call to get covered.