Security Update Advisory for Apache Tomcat September Vulnerability

Security Update Advisory for Apache Tomcat September Vulnerability
  • A security update has been released for Apache Tomcat (web application server).
  • Affected products include Apache Tomcat versions 9.0.0.M1 through 9.0.121, 10.1.0-M1 through 10.1.59, And 11.0.0-M1 through 11.0.25.
  • A total of 12 vulnerabilities have been addressed, including a certificate validation vulnerability (CVE-2026-73581, CVSS 6.5), An authentication vulnerability (CVE-2026-75973, CVSS 7.3), An authentication bypass vulnerability (CVE-2026-76183, CVSS 9.8), An HTTP request smuggling vulnerability (CVE-2026-77756, CVSS 3.7), HTTP/2-related vulnerabilities (CVE-2026-77762, CVSS 8.1, CVE-2026-78437, CVSS 7.3, CVE-2026-86350, CVSS 9.1), WebSocket-related vulnerabilities (CVE-2026-77791, CVSS 7.5, CVE-2026-87022, CVSS 7.5), An AJP-related denial-of-service vulnerability (CVE-2026-78383, CVSS 7.5), A missing timeout in asynchronous WebSocket write operations (CVE-2026-79677, CVSS 7.5), And a vulnerability related to CLIENT_CERT authentication (CVE-2026-86248, CVSS 9.8).
  • A certificate validation issue may occur because the TLS implementation in Apache Tomcat does not check the CRL (Certificate Revocation List) of certificates stored in the keystore.
  • The default SimpleAuthConfigProvider in Jakarta Authentication may cause authentication issues by reusing the Realm from the first application across multiple applications.
  • Bypassing security constraints on WebSocket endpoints is possible through alternate names.
  • HTTP request smuggling may occur due to an issue with handling the Transfer-Encoding header in HTTP/1.0 Requests, potentially causing other users’ requests to fail.
  • A race condition during HTTP/2 request processing could allow the insertion of a trailer field into another request; furthermore, abnormal HTTP/2 requests or incomplete handling of previous security fixes could cause other users’ requests to fail.
  • A denial-of-service condition may occur due to a busy-wait state during the transmission of WebSocket termination messages or due to improper handling of length parameters when using per-message-deflate.
  • Unrestricted resource allocation may allow unauthenticated AJP requests to monopolize processing threads, resulting in a denial-of-service condition.
  • In certain configurations, CLIENT_CERT authentication may not fail as expected, leading to certificate validation issues.
  • The security advisory was published on September 23, 2026, and Apache Tomcat does not provide binary Vulnerability Patches for individual vulnerabilities.
  • Depending on the product line in use, Apache Tomcat 9.X must be upgraded to version 9.0.122 Or later, 10.1.X to version 10.1.60 Or later, and 11.0.X to version 11.0.26 Or later.