GHSA-5m62-pw8w-7w9fCriticalCVSS 9.1

Apache Tomcat - Security constraints not correctly applied

Published
May 12, 2026
Last Modified
May 19, 2026

🔗 CVE IDs covered (1)

📋 Description

Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.21 Apache Tomcat 10.1.0-M1 to 10.1.54 Apache Tomcat 9.0.0.M1 to 9.0.117 Older, unsupported versions may also be affected Description: When multiple security constraints defined an HTTP method constraint for the same extension pattern, only the first method constraint was applied. Mitigation: Users of the affected versions should apply one of the following mitigations: - Upgrade to Apache Tomcat 11.0.22 or later - Upgrade to Apache Tomcat 10.1.55 or later - Upgrade to Apache Tomcat 9.0.118 or later

🎯 Affected products9

  • maven/org.apache.tomcat.embed:tomcat-embed-core:< 9.0.118
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 10.1.0-M1, < 10.1.55
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 11.0.0-M1, < 11.0.22
  • maven/org.apache.tomcat:tomcat:< 9.0.118
  • maven/org.apache.tomcat:tomcat:>= 10.1.0-M1, < 10.1.55
  • maven/org.apache.tomcat:tomcat:>= 11.0.0-M1, < 11.0.22
  • maven/org.apache.tomcat:tomcat-catalina:< 9.0.118
  • maven/org.apache.tomcat:tomcat-catalina:>= 10.1.0-M1, < 10.1.55
  • maven/org.apache.tomcat:tomcat-catalina:>= 11.0.0-M1, < 11.0.22

🔗 References (10)