
[CIVN-2026-0369] Multiple Vulnerabilities in Apache Tomcat
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in Apache Tomcat
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
Apache Tomcat 11 versions prior to 11.0.24
Apache Tomcat 10.1 versions prior to 10.1.57
Apache Tomcat 9 versions prior to 9.0.120
Apache Tomcat versions 8.5.38 through 8.5.100
Apache Tomcat versions 7.0.100 through 7.0.109
Overview
Multiple vulnerabilities have been reported in Apache Tomcat that could allow an attacker to bypass security restrictions or gain unauthorized access to protected resources on the affected system.
Target Audience:
All end user organizations and individuals responsible for maintaining and updating Apache Tomcat.
Risk Assessment:
Risk of security constraint bypass, unauthorized access, and insecure cluster communication configuration.
Impact Assessment:
Potential for unauthorized access to protected resources and weakened security of encrypted Tomcat cluster communications.
Description
Apache Tomcat is an open-source web server and servlet container used to deploy Java-based web applications.
Multiple vulnerabilities have been identified in Apache Tomcat due to improper handling of URL encoding (hex encoding) in the RewriteValve component and insufficient technical documentation for securely configuring the EncryptInterceptor component.
Successful exploitation of these vulnerabilities could allow an attacker to bypass security restrictions or gain unauthorized access to protected resources on the affected system.
Solution
Apply appropriate fixes as mentioned in the Apache Tomcat Security Updates:
https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.24
https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.57
https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.120
https://tomcat.apache.org/security-8.html
https://tomcat.apache.org/security-7.html
Vendor Information
Apache Tomcat
https://tomcat.apache.org/
References
https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.24
https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.57
https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.120
https://tomcat.apache.org/security-8.html
https://tomcat.apache.org/security-7.html
CVE Name
CVE-2026-59083
CVE-2026-59084
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmpfiGkACgkQ3jCgcSdc
ys8fgg//Z8LE76vBrTpJir5k0EE18ax8MEN/29PK4+kMEmOC2aHPnEgxOg6d+VF0
yMc5foP2/b9WqHm/ys2Im9SJTAkblr4IX/d72x2n2tY0QC15E9//7Qq7yOgJfjsK
otOWaDZM6B6wqAox6quN89JICICcLZ02KqIhL/9cHP1+GDC9h0SGsxmNWkWlNQj4
qRxO0VDj86edzYQeeqlLFhP7oAnn+jUjh1UQtfh5repZ9eSLPrkUN0a3Fya3Tmjq
qFkADujlHd+a1BPRYdJKHiFOz4VqhiCcHiNvMRe9+Xv4ehmyQHf5ZIVbx5uXMwpd
xUpKhvqcKxjPQIgx90lxrOqndD5Mn5VDE6IEZFDLsxE6Yd+iOeZT4mfc903+7mq+
h/+4wxuV5A0z7VmVHeYC1fSW43LQCKExksiJXy4slxFRdT2VGL+yGbBBfh3VohAi
rmy1ZD0s6pHhJvjh1s0XrILq6Je3TCVxOQ2CUiP7/1GWQfuLkil4MaRHcELa7Jxv
SLz5jnjRJTUlYUoyyxsNHmBFOWlpa4Z7WOAtP43LiA5c8EkH8YsEl/Y+H4JHmVOo
zoI+27zmtjc/hUA9MrMjyUZ3FvFTBn8aj99Jlt79/oxsCvPfgBlzRNVN2znJIR8s
qTL/35GI+hsLcTGhin0nyyTO3lvBJuTjDuXz668Ko1wyLzzFu1Q=
=WRk1
—–END PGP SIGNATURE—–


