GHSA-h6fc-48rj-7qqhCriticalCVSS 9.8

Apache Tomcat - Digest authenticator will authenticate any unknown user

Published
May 12, 2026
Last Modified
May 18, 2026

🔗 CVE IDs covered (1)

📋 Description

Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.21 Apache Tomcat 10.1.0-M1 to 10.1.54 Apache Tomcat 9.0.0.M1 to 9.0.117 Older, unsupported versions may also be affected Description: When DIGEST authentication was configured, any user not known to the configured Realm would be authenticated if they presented the password "null". Mitigation: Users of the affected versions should apply one of the following mitigations: - Upgrade to Apache Tomcat 11.0.22 or later - Upgrade to Apache Tomcat 10.1.55 or later - Upgrade to Apache Tomcat 9.0.118 or later

🎯 Affected products9

  • maven/org.apache.tomcat.embed:tomcat-embed-core:< 9.0.118
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 10.1.0-M1, < 10.1.55
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 11.0.0-M1, < 11.0.22
  • maven/org.apache.tomcat:tomcat:< 9.0.118
  • maven/org.apache.tomcat:tomcat:>= 10.1.0-M1, < 10.1.55
  • maven/org.apache.tomcat:tomcat:>= 11.0.0-M1, < 11.0.22
  • maven/org.apache.tomcat:tomcat-catalina:< 9.0.118
  • maven/org.apache.tomcat:tomcat-catalina:>= 10.1.0-M1, < 10.1.55
  • maven/org.apache.tomcat:tomcat-catalina:>= 11.0.0-M1, < 11.0.22

🔗 References (10)