oss-sec mailing list archives
CVE-2026-43515: Apache Tomcat: Security constraints not correctly applied
From: Mark Thomas <markt () apache org>
Date: Tue, 12 May 2026 16:34:36 +0100
Severity: moderate Affected versions: - Apache Tomcat 11.0.0-M1 through 11.0.21 - Apache Tomcat 10.1.0-M1 through 10.1.54 - Apache Tomcat 9.0.0.M1 through 9.0.117 - Apache Tomcat 8.5.0 through 8.5.100 - Apache Tomcat 7.0.0 through 7.0.109 - Apache Tomcat before 7.00 unknown Description:Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
References: https://lists.apache.org/thread/746nxfxod0wsocxtmv8pb8nkgmwpc6bb https://tomcat.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-43515
Current thread:
- CVE-2026-43515: Apache Tomcat: Security constraints not correctly applied Mark Thomas (May 12)
