Junglewise Threat Intelligence

CVE-2026-65183: Apache Tomcat TOCTOU race condition in Unix domain socket creation

CVE-2026-65183 · Severity: high · CVSS 8.1 · Published 2026-08-25

Technologies: Apache Tomcat. Vendors: Apache.

Executive brief

Apache Tomcat is a widely-used application server that handles HTTP requests and runs Java applications. A race condition in how Tomcat creates Unix domain sockets—a local inter-process communication mechanism—allows an unauthorized local attacker to access these sockets and potentially bypass security controls. This could enable an attacker with local system access to escalate privileges or access sensitive application data.

Technical details

A Time-of-check Time-of-use (TOCTOU) race condition exists in Apache Tomcat's Unix domain socket creation logic. An attacker with local system access can exploit the window between when Tomcat checks socket permissions and when it actually creates the socket with restricted access, allowing them to interfere with socket creation. This permits an unauthorized local user to gain access to the Unix domain socket before proper permissions are enforced. Affected versions are Tomcat 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, and 9.0.42 through 9.0.120. The vulnerability has been patched in versions 11.0.25, 10.1.58, and 9.0.121.

Affected products

  • Apache Tomcat 11.0.0-M1 through 11.0.24, 10.1.0-M1 through 10.1.57, 9.0.42 through 9.0.120

Timeline

  • 2026-08-25: disclosed
  • 2026-08-25: patched: Fixes available in versions 11.0.25, 10.1.58, 9.0.121

References

Related threats