LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-43513

apache · tomcat

Published
CVSS7.5
Severityhigh
WeaknessCWE-178
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Description

Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-43513

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-43513.