oss-sec mailing list archives
CVE-2026-34487: Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token
From: Mark Thomas <markt () apache org>
Date: Thu, 9 Apr 2026 20:51:14 +0100
Severity: low Affected versions: - Apache Tomcat 11.0.0-M1 through 11.0.20 - Apache Tomcat 10.1.0-M1 through 10.1.53 - Apache Tomcat 9.0.13 through 9.0.116 Description:Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Credit: Bartlomiej Dmitruk, striga.ai (finder) References: https://lists.apache.org/thread/4xpkwolpkrj8v5xzp5nyovtlqp3y850h https://tomcat.apache.org/ https://www.cve.org/CVERecord?id=CVE-2026-34487
Current thread:
- CVE-2026-34487: Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token Mark Thomas (Apr 09)
