All vulnerabilities
CVE-2026-41284
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
Description
Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.21 Apache Tomcat 10.1.0-M1 to 10.1.54 Apache Tomcat 9.0.0.M1 to 9.0.117 Older, unsupported versions may also be affected
Description: No limit was enforced on the request body for WebDAV LOCK or PROPFIND requests which were available to unauthenticated users.
Mitigation: Users of the affected versions should apply one of the following mitigations:
- Upgrade to Apache Tomcat 11.0.22 or later
- Upgrade to Apache Tomcat 10.1.55 or later
- Upgrade to Apache Tomcat 9.0.118 or later
Credit: This issue was identified by Dariusz Gońda
Patch Available
Fix available through Seal Security. No upgrade required, protect your application instantly.
Fix without upgrading
Score
7.5
Severity
High
Ecosystem
Java
Publish Date
May 12, 2026
Modified Date
May 19, 2026
Score Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Versions

