Apache Tomcat remediated a group of vulnerabilities affecting multiple supported release lines. CVE-2026-55957 allows authentication bypass in JNDIRealm deployments that use GSSAPI-authenticated binds, while CVE-2026-55956 can cause Default Servlet security constraints to incorrectly handle specified HTTP methods or method omissions. CVE-2026-55955 permits replay attacks against the cluster-component EncryptionInterceptor, and CVE-2026-43514 exposes a timing discrepancy in AJP secret comparison that may aid secret-value inference.
Tomcat also corrected CVE-2026-53434, in which invalid certificate-revocation-list configuration for an FFM-based connector might not produce an error, and CVE-2026-55276, where effective web.xml logging could omit special roles and empty authorization constraints. Organizations should upgrade affected deployments to supported fixed releases: generally Tomcat 11.0.23, 10.1.56, or 9.0.119 for the June issues; the JNDIRealm authentication-bypass advisory specifies 11.0.5, 10.1.37, or 9.0.101. Tomcat 8.0 and 8.5 are end of life and should be migrated to a supported branch rather than retained without security fixes.

See affected versions and whether adversaries are exploiting it.
31 events from the most recent confirmed update back to the earliest known activity.
Apache published CVE-2026-55957, a missing authentication step in GSSAPI-authenticated JNDIRealm binds that could allow authentication without the correct password. Apache recommended upgrading to Tomcat 11.0.5, 10.1.37, or 9.0.101.
Apache published CVE-2026-55956, under which Default Servlet security constraints could ignore configured HTTP methods or method omissions. Apache fixed the issue in Tomcat 11.0.23, 10.1.56, and 9.0.119.
Apache published CVE-2026-55955, an improper-authentication issue permitting replay attacks against the cluster component's EncryptionInterceptor. Apache identified 11.0.23, 10.1.56, and 9.0.119 as fixed releases.
Apache published CVE-2026-55276, which could omit special roles and empty authorization constraints from logged effective web.xml output. Apache directed affected users to fixed 11.0.23, 10.1.56, or 9.0.119 releases.
Apache published CVE-2026-53434, where invalid certificate-revocation-list configuration on an FFM-based connector did not trigger an appropriate error or failure. Fixed releases were Tomcat 11.0.23, 10.1.56, and 9.0.119.
Apache published CVE-2026-43514, an observable timing discrepancy in AJP-secret comparison affecting several Tomcat release lines. Apache identified Tomcat 11.0.22, 10.1.55, and 9.0.118 as fixed releases.
Apache Tomcat 9.0.121 was released with fixes including WebSocket sessions surviving changed HTTP-session IDs (CVE-2026-73180), HTTP/2 backlog allocation leakage, realm authentication and role-constraint bypasses, RewriteValve access-control issues, DIGEST replay, Unix-domain-socket permissions, and WebSocket example memory exhaustion.
Tomcat addressed CVE-2025-55752, which enabled RewriteValve directory traversal and security-constraint bypass. Remote code execution was possible where PUT was enabled and malicious files could be uploaded.
Tomcat addressed CVE-2025-48989, exposing its HTTP/2 implementation to the made-you-reset attack and potentially causing an OutOfMemoryError denial of service.
Tomcat addressed CVE-2025-53506, in which a client could cause denial of service through excessive HTTP/2 streams by failing to acknowledge a settings frame that reduced concurrent-stream limits.
Tomcat addressed CVE-2025-48988 and CVE-2025-48976, multipart-upload memory-exhaustion vulnerabilities, by adding configurable maxPartCount and maxPartHeaderSize limits.
Tomcat fixed CVE-2025-24813, under which a write-enabled Default Servlet could expose or modify sensitive files through partial PUT; remote code execution was possible with additional FileStore persistence and deserialization prerequisites.
Tomcat fixed CVE-2024-50379, which could enable remote code execution on case-insensitive filesystems when the Default Servlet was write-enabled and concurrent reads/uploads bypassed case-sensitivity checks. CVE-2024-56337 addressed an incomplete mitigation and required Java 8 or 11 users in the affected configuration to disable the canonical-path cache.
Apache Tomcat 8.5.99 fixed CVE-2024-23672, allowing a client to retain a WebSocket connection and increase resource consumption, and CVE-2024-24549, involving delayed HTTP/2 stream resets after header limits were exceeded.
Apache Tomcat 8.5.96 fixed CVE-2023-46589, a request-smuggling vulnerability involving oversized HTTP trailer headers behind a reverse proxy.
Apache Tomcat 8.5.94 fixed CVE-2023-44487 (HTTP/2 rapid reset), CVE-2023-45648 (trailer-header request smuggling), and CVE-2023-42795 (request/response object recycling data disclosure).
Apache Tomcat 8.5.88 fixed CVE-2023-28709, which could bypass uploaded request-part limits under specific non-default connector settings.
Apache Tomcat 8.5.86 fixed CVE-2023-28708, where RemoteIpFilter could fail to mark session cookies Secure when HTTPS was indicated through X-Forwarded-Proto.
Apache Tomcat 8.5.85 fixed CVE-2023-24998, a denial-of-service issue in its renamed Apache Commons FileUpload copy that did not limit the number of processed request parts.
Apache Tomcat 8.5.78 fixed CVE-2021-43980, which could cause separate client connections to share an Http11Processor and receive another client's response data.
Apache Tomcat 8.5.76 fixed CVE-2022-25762, in which concurrent reuse of a pooled WebSocket object could return data to the wrong user.
Apache Tomcat 8.5.75 fixed CVE-2022-23181, a local privilege-escalation issue caused by a time-of-check/time-of-use flaw when FileStore session persistence was used.
Apache Tomcat 8.5.68 fixed CVE-2021-33037, involving incorrect parsing of HTTP Transfer-Encoding headers when deployed behind a reverse proxy.
Apache Tomcat 8.5.64 fixed CVE-2021-41079, where crafted TLS traffic could cause an infinite loop in NIO+OpenSSL or NIO2+OpenSSL configurations.
Apache Tomcat 8.5.63 fixed CVE-2024-21733, in which incomplete POST requests could produce error responses containing data from an earlier user's request.
Apache Tomcat 8.5.60 fixed CVE-2021-24122, an information-disclosure issue involving resources served from NTFS network locations that could bypass constraints or expose JSP source.
Apache Tomcat 8.5.55 fixed CVE-2020-9484, which could deserialize an attacker-controlled server file when FileStore session persistence and a permissive class filter were configured.
Apache Tomcat 8.5.51 fixed CVE-2020-1938 (Ghostcat). An attacker able to access an untrusted AJP port could read web-application files or process files as JSPs, with remote code execution possible under additional content-control conditions.
Apache Tomcat 8.5.40 fixed CVE-2019-0232, affecting Windows systems where both the disabled-by-default CGI Servlet and enableCmdLineArguments option had been enabled.
Apache Tomcat 8.5.38 fixed CVE-2019-0199, an HTTP/2 denial-of-service issue that could retain streams using blocking I/O and exhaust server threads.
Apache Tomcat 8.5.23 fixed CVE-2017-12617, which could permit remote code execution if HTTP PUT was enabled and an attacker could upload a JSP file.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
10 references tracked. Mallory keeps watching after this page renders.
tomcat.apache.org
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourcecve.mitre.org
Open sourcetomcat.apache.org
Open sourcemail-archives.apache.org
Open sourcetomcat.apache.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.