The Apache Software Foundationから、Apache Tomcatの15件の脆弱性に対してアドバイザリが公開されました。 Fixed in Apache Tomcat 11.0.26Fixed in Apache Tomcat 10.1.60Fixed in Apache Tomcat 9.0.122Fixed in Apache Tomcat Native Connector 2.0.16 / 1.3.9
Apache Software Foundation Apache Tomcat
Apache Tomcatのアドバイザリを参照してください。
Apache Software Foundation The Apache Software Foundation : [SECURITY] CVE-2026-73581 Apache Tomcat - OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore The Apache Software Foundation : [SECURITY] CVE-2026-75973 Apache Tomcat - Cross-context authentication mix-up with Jakarta Authentication configured The Apache Software Foundation : [SECURITY] CVE-2026-76183 Apache Tomcat - Bypass of security constraints for WebSocket endpoints The Apache Software Foundation : [SECURITY] CVE-2026-77756 Apache Tomcat - Transfer-Encoding honored for HTTP/1.0 requests The Apache Software Foundation : [SECURITY] CVE-2026-77762 Apache Tomcat - Stale HPACK emitter injects trailers into recycled pooled Request The Apache Software Foundation : [SECURITY] CVE-2026-77791 Apache Tomcat - DoS via busy wait during WebSocket close The Apache Software Foundation : [SECURITY] CVE-2026-78383 Apache Tomcat - AJP DoS via missing request body The Apache Software Foundation : [SECURITY] CVE-2026-78437 Apache Tomcat - HTTP/2 DoS via malformed request The Apache Software Foundation : [SECURITY] CVE-2026-79677 Apache Tomcat - WebSocket DoS due to lost asynchronous write timeout The Apache Software Foundation : [SECURITY] CVE-2026-86243 Apache Tomcat Native - DoS via TLS handshake The Apache Software Foundation : [SECURITY] CVE-2026-86246 Apache Tomcat Native - Insecure OpenSSL options enabled The Apache Software Foundation : [SECURITY] CVE-2026-86247 Apache Tomcat Native - Client certificate requirements can be down-graded The Apache Software Foundation : [SECURITY] CVE-2026-86248 Apache Tomcat - Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled The Apache Software Foundation : [SECURITY] CVE-2026-86350 Apache Tomcat - Regression in fix for CVE-2026-41293 can trigger request header mix-up The Apache Software Foundation : [SECURITY] CVE-2026-87022 Apache Tomcat - WebSocket message smuggling with per-message-deflate
CVE-2026-34500 CVE-2026-41293 CVE-2026-73581 CVE-2026-75973 CVE-2026-76183 CVE-2026-77756 CVE-2026-77762 CVE-2026-77791 CVE-2026-78383 CVE-2026-78437 CVE-2026-79677 CVE-2026-86243 CVE-2026-86246 CVE-2026-86247 CVE-2026-86248 CVE-2026-86350 CVE-2026-87022
JVN : JVNVU#94625787
[2026年09月25日] 掲載