CVE-2026-43512
DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0. Older unsupported versions any also be affect Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 1.23%
- CWE
- CWE-592
- Published
- 2026-05-12
- Last modified
- 2026-05-14
Affected products
- Apache Software Foundation Apache Tomcat
- Apache Software Foundation Apache Tomcat
- Apache Software Foundation Apache Tomcat
- Apache Software Foundation Apache Tomcat
- Apache Software Foundation Apache Tomcat
- Apache Software Foundation Apache Tomcat
Weakness type
Related vulnerabilities
- CVE-2023-30971 — Gaia unauthenticated endpoints
- CVE-2019-14843 — A flaw was found in Wildfly Security Manager, running under JDK 11 or 8, that authorized requests...
- CVE-2019-14910 — A vulnerability was found in keycloak 7.x, when keycloak is configured with LDAP user federation...
- CVE-2019-14909 — A vulnerability was found in Keycloak 7.x where the user federation LDAP bind type is none (LDAP...
- CVE-2019-10201 — It was found that Keycloak's SAML broker, versions up to 6.0.1, did not verify missing message...
- CVE-2019-10198 — An authentication bypass vulnerability was discovered in foreman-tasks before 0.15.7. Previously,...
- CVE-2019-3899 — It was found that default configuration of Heketi does not require any authentication potentially...
- CVE-2014-5432 — Baxter SIGMA Spectrum Infusion System version 6.05 (model 35700BAX) with wireless battery module...