Executive brief
Apache Tomcat is a Java-based application server used to run web applications and services. A security constraint bypass vulnerability in WebSocket endpoints allows attackers to access protected resources without proper authentication, potentially exposing sensitive data or enabling unauthorized actions on affected systems.
Technical details
An authentication bypass vulnerability in Apache Tomcat's WebSocket endpoint handling allows attackers to bypass security constraints through alternate name manipulation. The vulnerability affects multiple versions across major release lines and requires network access to WebSocket endpoints. A fix is available in versions 11.0.26, 10.1.60, and 9.0.122.
Affected products
- Apache Tomcat 11.0.0-M1 through 11.0.25
- Apache Tomcat 10.1.0-M1 through 10.1.59
- Apache Tomcat 9.0.0-M1 through 9.0.121
- Apache Tomcat 8.5.0 through 8.5.100
- Apache Tomcat 7.0.43 through 7.0.109
Timeline
- 2026-09-23: disclosed
- 2026-09-23: patched: Fixed in Tomcat 11.0.26, 10.1.60, and 9.0.122