[CIVN-2026-0369] Multiple Vulnerabilities in Apache Tomcat

By Published On: July 21, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in Apache Tomcat


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


Apache Tomcat 11 versions prior to 11.0.24

Apache Tomcat 10.1 versions prior to 10.1.57

Apache Tomcat 9 versions prior to 9.0.120

Apache Tomcat versions 8.5.38 through 8.5.100

Apache Tomcat versions 7.0.100 through 7.0.109

Overview



Multiple vulnerabilities have been reported in Apache Tomcat that could allow an attacker to bypass security restrictions or gain unauthorized access to protected resources on the affected system.


Target Audience:

All end user organizations and individuals responsible for maintaining and updating Apache Tomcat.


Risk Assessment:

Risk of security constraint bypass, unauthorized access, and insecure cluster communication configuration.


Impact Assessment:

Potential for unauthorized access to protected resources and weakened security of encrypted Tomcat cluster communications.


Description


Apache Tomcat is an open-source web server and servlet container used to deploy Java-based web applications.


Multiple vulnerabilities have been identified in Apache Tomcat due to improper handling of URL encoding (hex encoding) in the RewriteValve component and insufficient technical documentation for securely configuring the EncryptInterceptor component.


Successful exploitation of these vulnerabilities could allow an attacker to bypass security restrictions or gain unauthorized access to protected resources on the affected system.


Solution


Apply appropriate fixes as mentioned in the Apache Tomcat Security Updates:

https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.24


https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.57


https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.120


https://tomcat.apache.org/security-8.html


https://tomcat.apache.org/security-7.html



Vendor Information


Apache Tomcat

https://tomcat.apache.org/


References


 

https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.24

https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.57

https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.120

https://tomcat.apache.org/security-8.html

https://tomcat.apache.org/security-7.html


CVE Name

CVE-2026-59083

CVE-2026-59084




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpfiGkACgkQ3jCgcSdc

ys8fgg//Z8LE76vBrTpJir5k0EE18ax8MEN/29PK4+kMEmOC2aHPnEgxOg6d+VF0

yMc5foP2/b9WqHm/ys2Im9SJTAkblr4IX/d72x2n2tY0QC15E9//7Qq7yOgJfjsK

otOWaDZM6B6wqAox6quN89JICICcLZ02KqIhL/9cHP1+GDC9h0SGsxmNWkWlNQj4

qRxO0VDj86edzYQeeqlLFhP7oAnn+jUjh1UQtfh5repZ9eSLPrkUN0a3Fya3Tmjq

qFkADujlHd+a1BPRYdJKHiFOz4VqhiCcHiNvMRe9+Xv4ehmyQHf5ZIVbx5uXMwpd

xUpKhvqcKxjPQIgx90lxrOqndD5Mn5VDE6IEZFDLsxE6Yd+iOeZT4mfc903+7mq+

h/+4wxuV5A0z7VmVHeYC1fSW43LQCKExksiJXy4slxFRdT2VGL+yGbBBfh3VohAi

rmy1ZD0s6pHhJvjh1s0XrILq6Je3TCVxOQ2CUiP7/1GWQfuLkil4MaRHcELa7Jxv

SLz5jnjRJTUlYUoyyxsNHmBFOWlpa4Z7WOAtP43LiA5c8EkH8YsEl/Y+H4JHmVOo

zoI+27zmtjc/hUA9MrMjyUZ3FvFTBn8aj99Jlt79/oxsCvPfgBlzRNVN2znJIR8s

qTL/35GI+hsLcTGhin0nyyTO3lvBJuTjDuXz668Ko1wyLzzFu1Q=

=WRk1

—–END PGP SIGNATURE—–

Share this article