Files
llm-wiki/raw/articles/tomcat-cve-2026-55957-auth-bypass-2026.md
2026-07-03 00:38:05 +09:00

734 lines
48 KiB
Markdown

---
source_url: "https://tomcat.apache.org/security-11.html"
ingested: 2026-07-01
sha256: 1279cc8a782fd507db9ef546c2aa59b5986970778d0482b2a3bfa007d947c6fd
discovered_from:
platform: discord
channel_id: "1477793137064935675"
channel_name: "tw"
message_id: "1521732555231989872"
author_id: "1477793167486226708"
posted_at: "2026-07-01T04:21:53.591000000Z"
message_excerpt: >-
Apache Tomcat 11 CVE-2026-55957 authentication bypass with JNDIRealm and GSSAPI authenticated bind.
---
### Apache Tomcat 11.x vulnerabilities
This page lists all security vulnerabilities fixed in released versions of Apache Tomcat <sup>®</sup> 11.x. Each vulnerability is given a [security impact rating](https://tomcat.apache.org/security-impact.html) by the Apache Tomcat security team — please note that this rating may vary from platform to platform. We also list the versions of Apache Tomcat the flaw is known to affect, and where a flaw has not been verified list the version with a question mark.
**Note:** Vulnerabilities that are not Tomcat vulnerabilities but have either been incorrectly reported against Tomcat or where Tomcat provides a workaround are listed at the end of this page.
Please note that binary patches are never provided. If you need to apply a source code patch, use the building instructions for the Apache Tomcat version that you are using. For Tomcat 11.0.x those are [`building.html`](https://tomcat.apache.org/tomcat-11.0-doc/building.html) and [`BUILDING.txt`](https://tomcat.apache.org/tomcat-11.0-doc/BUILDING.txt). Both files can be found in the `webapps/docs` subdirectory of a binary distribution. You may also want to review the [Security Considerations](https://tomcat.apache.org/tomcat-11.0-doc/security-howto.html) page in the documentation.
If you need help on building or configuring Tomcat or other help on following the instructions to mitigate the known vulnerabilities listed here, please send your questions to the public [Tomcat Users mailing list](https://tomcat.apache.org/lists.html)
If you have encountered an unlisted security vulnerability or other unexpected behaviour that has [security impact](https://tomcat.apache.org/security-impact.html), or if the descriptions here are incomplete, please report them privately to the [Tomcat Security Team](https://tomcat.apache.org/security.html). Thank you.
### Table of Contents
- [Fixed in Apache Tomcat 11.0.23](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.23)
- [Fixed in Apache Tomcat 11.0.22](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.22)
- [Fixed in Apache Tomcat 11.0.21](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.21)
- [Fixed in Apache Tomcat 11.0.20](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.20)
- [Fixed in Apache Tomcat 11.0.18](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.18)
- [Fixed in Apache Tomcat 11.0.15](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.15)
- [Fixed in Apache Tomcat 11.0.12](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.12)
- [Fixed in Apache Tomcat 11.0.11](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.11)
- [Fixed in Apache Tomcat 11.0.10](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.10)
- [Fixed in Apache Tomcat 11.0.9](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.9)
- [Fixed in Apache Tomcat 11.0.8](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.8)
- [Fixed in Apache Tomcat 11.0.7](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.7)
- [Fixed in Apache Tomcat 11.0.6](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.6)
- [Fixed in Apache Tomcat 11.0.5](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.5)
- [Fixed in Apache Tomcat 11.0.3](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.3)
- [Fixed in Apache Tomcat 11.0.2](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.2)
- [Fixed in Apache Tomcat 11.0.1](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.1)
- [Fixed in Apache Tomcat 11.0.0](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.0)
- [Fixed in Apache Tomcat 11.0.0-M21](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.0-M21)
- [Fixed in Apache Tomcat 11.0.0-M17](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.0-M17)
- [Fixed in Apache Tomcat 11.0.0-M12](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.0-M12)
- [Fixed in Apache Tomcat 11.0.0-M11](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.0-M11)
- [Fixed in Apache Tomcat 11.0.0-M6](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.0-M6)
- [Fixed in Apache Tomcat 11.0.0-M5](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.0-M5)
- [Fixed in Apache Tomcat 11.0.0-M3](https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.0-M3)
### 2026-06-22 Fixed in Apache Tomcat 11.0.23
**Moderate: Security constraints for default servlet ignored method** [CVE-2026-55956](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55956)
If security constraints were specified for the default servlet, any method or method omission configured as part of the constraint was ignored.
This was fixed with commits [3f6bd2ba](https://github.com/apache/tomcat/commit/3f6bd2ba5e53d1f340bbe5ad2d42a28b29440b7a).
This issue was reported to the Tomcat security team on 15 June 2026. The issue was made public on 29 June 2026.
Affects: 11.0.0-M1 to 11.0.22
**Low: EncryptInterceptor not protected against replay attacks** [CVE-2026-55955](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55955)
Contrary to the documentation, the EncryptInterceptor was not protected against replay attacks.
This was fixed with commits [5e594400](https://github.com/apache/tomcat/commit/5e594400c7f6ac0eaf2526bd64442a70f5ccaace).
This issue was reported to the Tomcat security team on 17 June 2026. The issue was made public on 29 June 2026.
Affects: 11.0.0-M1 to 11.0.22
**Low: Logged effective web.xml is incomplete** [CVE-2026-55276](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55276)
Logic errors in the effective web.xml generation meant that neither special roles nor empty authorization constraints were included in the logged effective web.xml.
This was fixed with commits [f844614c](https://github.com/apache/tomcat/commit/f844614c6d92eeb11e81e179606bf4c390f642dd) and [e391c6b2](https://github.com/apache/tomcat/commit/e391c6b201eae2ad9707a1335aff68ab8b3e0f84).
This issue was reported to the Tomcat security team on 16 June 2026. The issue was made public on 29 June 2026.
Affects: 11.0.0-M1 to 11.0.22
**Low: Invalid CRL configuration doesn't trigger failure for FFM Connector** [CVE-2026-53434](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-53434)
If an FFM connector was configured with invalid CRLs, the invalid CRLs were ignored meaning invalid certificates could be accepted.
This was fixed with commits [7f8ecdbd](https://github.com/apache/tomcat/commit/7f8ecdbd930d8c5a7fae73aa0eec9124d919e2f5).
This issue was reported to the Tomcat security team on 8 June 2026. The issue was made public on 29 June 2026.
Affects: 11.0.0-M1 to 11.0.22
**Low: Bad ornext processing in RewriteValve** [CVE-2026-53404](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-53404)
If a request matched the first condition in an OR chain, subsequent non-OR conditions were skipped and the rewrite succeeded.
This was fixed with commits [b647cb58](https://github.com/apache/tomcat/commit/b647cb584cea8bf95e64f5d2526c59ab8fca3225).
This issue was reported to the Tomcat security team on 28 May 2026. The issue was made public on 29 June 2026.
Affects: 11.0.0-M1 to 11.0.22
**Low: XSS in number guess example** [CVE-2026-50229](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-50229)
The use of wild card property mapping resulted in some properties, that were intended to be internal only, being exposed to clients allowing an XSS attack.
This was fixed with commits [1fe95d84](https://github.com/apache/tomcat/commit/1fe95d841e9d461a16069974142d12c3ef68819a).
This issue was reported to the Tomcat security team on 11 May 2026. The issue was made public on 29 June 2026.
Affects: 11.0.0-M1 to 11.0.22
### 2026-05-05 Fixed in Apache Tomcat 11.0.22
**Moderate: Security constraints not correctly applied** [CVE-2026-43515](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43515)
When multiple security constraints defined an HTTP method constraint for the same extension pattern, only the first method constraint was applied.
This was fixed with commits [276087d9](https://github.com/apache/tomcat/commit/276087d9c7abbcecc6c4fb4e4b08cf64780c6e36) and [06597486](https://github.com/apache/tomcat/commit/0659748659ec75253fea5aac72cab6f94e79c419).
This issue was reported to the Tomcat security team on 20 April 2026. The issue was made public on 12 May 2026.
Affects: 11.0.0-M1 to 11.0.21
**Low: AJP secret compared in non-constant time** [CVE-2026-43514](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43514)
The AJP secret was compared in non-constant time allowing an attacker on the local network to mount a timing attack to determine the AJP secret.
This was fixed with commit [d35d9d23](https://github.com/apache/tomcat/commit/d35d9d23263c8e4af561f615c960c91697ff200e).
This issue was reported to the Tomcat security team on 20 April 2026. The issue was made public on 12 May 2026.
Affects: 11.0.0-M1 to 11.0.21
**Low: LockOutRealm treats user names as case-sensitive** [CVE-2026-43513](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43513)
The LockOut Realm treated user names as case sensitive meaning that, for Realms where the user name was case insensitive, the LockOut Realm was not as effective at blocking brute force attacks against a user's password.
This was fixed with commit [83f3e51d](https://github.com/apache/tomcat/commit/83f3e51df7b87f5f6e626951c575ded1a512e8ef).
This issue was reported to the Tomcat security team on 20 April 2026. The issue was made public on 12 May 2026.
Affects: 11.0.0-M1 to 11.0.21
**Moderate: Digest authenticator will authenticate any unknown user** [CVE-2026-43512](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-43512)
When DIGEST authentication was configured, any user not known to the configured Realm would be authenticated if they presented the password "null".
This was fixed with commit [a99c355e](https://github.com/apache/tomcat/commit/a99c355e8199adbfd67c9a1fffbd85b810b196cd).
This issue was reported to the Tomcat security team on 20 April 2026. The issue was made public on 12 May 2026.
Affects: 11.0.0-M1 to 11.0.21
**Low: WebSocket authentication header exposure** [CVE-2026-42498](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-42498)
If a WebSocket request was redirected after authentication, Tomcat's WebSocket client would present the most recent authentication header to the redirect target host.
This was fixed with commit [b7b17369](https://github.com/apache/tomcat/commit/b7b173694d588ddcfa432f079baf763cbbbaa5c4).
This issue was reported to the Tomcat security team on 21 April 2026. The issue was made public on 12 May 2026.
Affects: 11.0.0-M1 to 11.0.21
**Low: HTTP/2 request headers not validated** [CVE-2026-41293](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41293)
HTTP/2 request headers were not validated which may have triggered unexpected application behaviour if the application (quite reasonably) assumed that header value exposed through the Servlet API would be specification compliant.
This was fixed with commits [e5cef961](https://github.com/apache/tomcat/commit/e5cef9618c3f4fd31bd6fb1e83f0f18022280dac), [3915fd27](https://github.com/apache/tomcat/commit/3915fd27e6810b14ccd21e3d900bd8faef44d3df) and [c2925554](https://github.com/apache/tomcat/commit/c2925554c677da57390f940d856871e18daaacab).
This issue was reported to the Tomcat security team on 15 April 2026. The issue was made public on 12 May 2026.
Affects: 11.0.0-M1 to 11.0.21
**Low: Unbounded read in WebDAV LOCK and PROPFIND handling** [CVE-2026-41284](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-41284)
No limit was enforced on the request body for WebDAV LOCK or PROPFIND requests which were available to unauthenticated users.
This was fixed with commit [a96fffd1](https://github.com/apache/tomcat/commit/a96fffd18487a29c0a30d36f00cb2b2d91f6d42c).
This issue was reported to the Tomcat security team on 11 April 2026. The issue was made public on 12 May 2026.
Affects: 11.0.0-M1 to 11.0.21
### 2026-04-04 Fixed in Apache Tomcat 11.0.21
**Moderate: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled** [CVE-2026-34500](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34500)
CLIENT\_CERT authentication did not fail as expected for some scenarios when soft fail was disabled and FFM was used.
This was fixed with commit [c13e60e7](https://github.com/apache/tomcat/commit/c13e60e732ea6d07087293a41ad1866c20848271).
This issue was reported to the Tomcat security team on 25 March 2026. The issue was made public on 9 April 2026.
Affects: 11.0.0-M14 to 11.0.20
**Low: Cloud membership for clustering component exposed the Kubernetes bearer token** [CVE-2026-34487](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34487)
The cloud membership for clustering component exposed the Kubernetes bearer token in log messages.
This was fixed with commit [301bc6ef](https://github.com/apache/tomcat/commit/301bc6efbf72feb14dacfdfa3f50372182736150).
This issue was reported to the Tomcat security team on 25 March 2026. The issue was made public on 9 April 2026.
Affects: 11.0.0-M1 to 11.0.20
**Important: The fix for [CVE-2026-29146](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29146) allowed the bypass of the EncryptInterceptor** [CVE-2026-34486](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34486)
An error in the fix for [CVE-2026-29146](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29146) allowed the EncryptInterceptor to be bypassed.
This was fixed with commit [1fab40cc](https://github.com/apache/tomcat/commit/1fab40ccc752e22639eccfe290d5624afad7eccd).
This issue was reported to the Tomcat security team on 26 March 2026. The issue was made public on 9 April 2026.
Affects: 11.0.20
**Low: Incomplete escaping of JSON access logs** [CVE-2026-34483](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-34483)
Incomplete escaping when non-default values were used for the Connector attributes relaxedPathChars and/or relaxedQueryChars allowed the injection of arbitrary JSON into the JSON access log.
This was fixed with commit [f9ddc24f](https://github.com/apache/tomcat/commit/f9ddc24fcfcdfaea4a6953198d8636aca3e957bc).
This issue was reported to the Tomcat security team on 25 March 2026. The issue was made public on 9 April 2026.
Affects: 11.0.0-M1 to 11.0.20
### 2026-03-20 Fixed in Apache Tomcat 11.0.20
**Moderate: The fix for [CVE-2025-66614](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66614) was incomplete** [CVE-2026-32990](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-32990)
The validation of SNI name and host name did not take account of possible differences in case allowing the strict SNI checks to be bypassed.
This was fixed with commit [021d1f83](https://github.com/apache/tomcat/commit/021d1f833e38b683a44688f7b28f1f27e8e37c36).
This issue was reported to the Tomcat security team on 13 March 2026. The issue was made public on 9 April 2026.
Affects: 11.0.15 to 11.0.19
*Note: The issues below were fixed in Apache Tomcat 11.0.19 but the release vote for the 11.0.19 release candidate did not pass. Therefore, although users must download 11.0.20 to obtain a version that includes a fix for these issues, version 11.0.19 is not included in the list of affected versions.*
**Important: EncryptInterceptor vulnerable to padding oracle attack by default** [CVE-2026-29146](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29146)
The EncryptInterceptor used CBC by default which is vulnerable to a padding Oracle attack.
This was fixed with commit [6d955cce](https://github.com/apache/tomcat/commit/6d955cceca841f2eabf2d6c46b59a8c7e1cd6eaa).
This issue was reported to the Tomcat security team on 22 February 2026. The issue was made public on 9 April 2026.
Affects: 11.0.0-M1 to 11.0.18
**Moderate: OCSP checks sometimes soft-fail even when soft-fail is disabled** [CVE-2026-29145](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29145)
CLIENT\_CERT authentication did not fail OCSP checks as expected for some scenarios when soft fail was disabled.
This was fixed with commit [721591f7](https://github.com/apache/tomcat/commit/721591f7bff424c693f26adc18ae9b9abac3655b).
This issue was reported to the Tomcat security team on 26 February 2026. The issue was made public on 9 April 2026.
Affects: 11.0.0-M1 to 11.0.18
**Low: Configured TLS cipher preference order not preserved** [CVE-2026-29129](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-29129)
The additional of the ability to configure TLS 1.3 cipher suites did not preserve the order of the configured cipher suites and ciphers.
This was fixed with commit [5cfa876d](https://github.com/apache/tomcat/commit/5cfa876d73f1ff5f4dc8309c4320f684cbeff74e).
This was reported as a bug on 20 February 026 and the security implications identified by the Tomcat security team the same day. The issue was made public on 9 April 2026.
Affects: 11.0.16 to 11.0.18
**Low: Occasionally open redirect** [CVE-2026-25854](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-25854)
When a Tomcat node in a cluster with the LoadBalancerDrainingValve was in the disabled (draining) state, a specially crafted URL could be used to trigger a redirect to a URI of the attackers choice.
This was fixed with commit [4c5d3060](https://github.com/apache/tomcat/commit/4c5d306001b780c9316aea5ff6502c524fb20695).
This issue was reported to the Tomcat security team on 30 January 2026. The issue was made public on 9 April 2026.
Affects: 11.0.0-M1 to 11.0.18
**Low: Request smuggling via invalid chunk extension** [CVE-2026-24880](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24880)
Tomcat did not validate that contents of HTTP/1.1 chunk extensions. This enabled a request smuggling attack if a reverse proxy in front of Tomcat allowed CRLF sequences in an otherwise valid chunk extension.
This was fixed with commits [fde1a823](https://github.com/apache/tomcat/commit/fde1a8235fb73125217bd41e162aa0a113f33552) and [2cb06c34](https://github.com/apache/tomcat/commit/2cb06c34f661ca42f7570bbcc21e99806184bcc5).
This issue was reported to the Tomcat security team on 19 January 2026. The issue was made public on 9 April 2026.
Affects: 11.0.0-M1 to 11.0.18
### 2026-01-26 Fixed in Apache Tomcat 11.0.18
**Moderate: Incomplete OCSP verification checks** [CVE-2026-24734](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24734)
When using an OCSP responder, Tomcat's FFM integration with OpenSSL did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed.
Affects: 11.0.0-M1 to 11.0.17
This issue was reported to the Tomcat security team on 2 November 2025. The issue was made public on 17 February 2026.
### 2025-12-08 Fixed in Apache Tomcat 11.0.15
**Low: Security constraint bypass** [CVE-2026-24733](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-24733)
Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9.
This was fixed with commit [6c73d74f](https://github.com/apache/tomcat/commit/6c73d74ff281260d74c836370ff6b82f1da8048b).
This issue was identified by the Tomcat security team on 26 November 2025. The issue was made public on 17 February 2026.
Affects: 11.0.0-M1 to 11.0.14
**Moderate: Client certificate verification bypass due to virtual host mapping** [CVE-2025-66614](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-66614)
Tomcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field.
The vulnerability only applies if client certificate authentication is only enforced at the Connector. It does not apply if client certificate authentication is enforced at the web application.
This was fixed with commit [258a591b](https://github.com/apache/tomcat/commit/258a591b61f8cf5c22109e21e5a2a38b63454fd2).
This issue was reported to the Tomcat security team on 15 October 2025. The issue was made public on 17 February 2026.
Affects: 11.0.0-M1 to 11.0.14
### 2025-10-07 Fixed in Apache Tomcat 11.0.12
**Low: Delayed cleaning of multipart upload temporary files may lead to DoS** [CVE-2025-61795](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-61795)
If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to local storage were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memory usage and application load, it was possible that space for the temporary copies of uploaded parts would be filled faster than GC cleared it, leading to a DoS.
This was fixed with commit [1cdf5f73](https://github.com/apache/tomcat/commit/1cdf5f730ede75a0759492f179ac21ca4ff68e06).
This issue was reported to the Tomcat security team on 7 September 2025. The issue was made public on 27 October 2025.
Affects: 11.0.0-M1 to 11.0.11
### 2025-09-05 Fixed in Apache Tomcat 11.0.11
**Low: Console manipulation via escape sequences in log messages** [CVE-2025-55754](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-55754)
Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI escape sequences to manipulate the console and the clipboard and attempt to trick an administrator into running an attacker controlled command. While no attack vector was found, it may have been possible to mount this attack on other operating systems.
This was fixed with commit [5a3db092](https://github.com/apache/tomcat/commit/5a3db092982c0c58d4855304167ee757fe5e79bb).
This issue was reported to the Tomcat security team on 5 August 2025. The issue was made public on 27 October 2025.
Affects: 11.0.0-M1 to 11.0.10
**Important: Directory traversal via Rewrite Valve with possible remote code execution if PUT is enabled** [CVE-2025-55752](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-55752)
The fix for bug [60013](https://bz.apache.org/bugzilla/show_bug.cgi?id=60013) introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the protection for `/WEB-INF/` and `/META-INF/`. If PUT requests were also enabled then malicious files could be uploaded leading to remote code execution. PUT requests are normally limited to trusted users and it is considered unlikely that PUT requests would be enabled in conjunction with a rewrite that manipulated the URI.
This was fixed with commit [fec06c61](https://github.com/apache/tomcat/commit/fec06c610ed7466b401e29cc567a58aee5ed826a).
This issue was reported to the Tomcat security team on 11 August 2025. The issue was made public on 27 October 2025.
Affects: 11.0.0-M1 to 11.0.10
### 2025-08-06 Fixed in Apache Tomcat 11.0.10
**Important: DoS in HTTP/2 due to client triggered stream reset** [CVE-2025-48989](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48989)
Tomcat's HTTP/2 implementation was vulnerable to the made you reset attack. The denial of service typically manifested as an `OutOfMemoryError`.
This was fixed with commit [f362c8eb](https://github.com/apache/tomcat/commit/f362c8eb3b8ec5b7f312f7f5610731c0fb299a06).
This issue was reported to the ASF security team on 29 May 2025. The issue was made public on 13 August 2025.
Affects: 11.0.0-M1 to 11.0.9
### 2025-07-04 Fixed in Apache Tomcat 11.0.9
**Low: DoS due to overflow in file upload limit** [CVE-2025-52520](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-52520)
For some unlikely configurations of multipart upload, an Integer Overflow vulnerability could lead to a DoS via bypassing of size limits.
This was fixed with commit [a51e4bed](https://github.com/apache/tomcat/commit/a51e4bedccfafd35b7cdd0ee3e22267dee9f90db).
This issue was reported to the Tomcat security team on 7 June 2025. The issue was made public on 10 July 2025.
Affects: 11.0.0-M1 to 11.0.8
**Important: DoS via excessive HTTP/2 streams** [CVE-2025-53506](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-53506)
An uncontrolled resource consumption vulnerability if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams could result in a DoS.
This was fixed with commit [be8f330f](https://github.com/apache/tomcat/commit/be8f330f83ceddaf3baeed57522e571572b6b99b).
This issue was reported to the Tomcat security team on 28 June 2025. The issue was made public on 10 July 2025.
Affects: 11.0.0-M1 to 11.0.8
### 2025-06-09 Fixed in Apache Tomcat 11.0.8
**Moderate: Session fixation possible via rewrite valve** [CVE-2025-55668](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-55668)
If the rewrite valve was enabled for a web application, an attacker was able to craft a URL that, if a victim clicked on it, would cause the victim's interaction with that resource to occur in the context of the attacker's session.
This was fixed with commit [90306d97](https://github.com/apache/tomcat/commit/90306d971bb8b8393336d893644124fb2ca11d21).
This issue was reported to the Tomcat security team on 30 May 2025. The issue was made public on 13 August 2025.
Affects: 11.0.0-M1 to 11.0.7
**Moderate: Security constraint bypass for PreResources and PostResources** [CVE-2025-49125](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-49125)
When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowing those security constraints to be bypassed.
This was fixed with commit [d94bd36f](https://github.com/apache/tomcat/commit/d94bd36fb7eb32e790dae0339bc249069649a637).
This issue was reported to the Tomcat security team on 30 May 2025. The issue was made public on 16 June 2025.
Affects: 11.0.0-M1 to 11.0.7
**Low: Side-loading via Tomcat installer for Windows** [CVE-2025-49124](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-49124)
During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This enabled a side-loading vulnerability.
This was fixed with commit [c56456cd](https://github.com/apache/tomcat/commit/c56456cda8151c9504dfb7985700824559d769a7).
This issue was reported to the Tomcat security team on 30 May 2025. The issue was made public on 16 June 2025.
Affects: 11.0.0-M1 to 11.0.7
**Important: DoS in multipart upload** [CVE-2025-48988](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48988)
Tomcat used the same limit for both request parameters and parts in a multipart request. Since uploaded parts also include headers which must be retained, processing multipart requests can result in significantly more memory usage. A specially crafted request that used a large number of parts could trigger excessive memory usage leading to a DoS. The maximum number of parts is now configurable (maxPartCount on the Connector) with a default of 10 parts.
This was fixed with commit [2b0ab14f](https://github.com/apache/tomcat/commit/2b0ab14fb55d4edc896e5f1817f2ab76f714ae5e).
This issue was reported to the ASF security team on 16 May 2025. The issue was made public on 16 June 2025.
Affects: 11.0.0-M1 to 11.0.7
**Important: DoS in Commons FileUpload** [CVE-2025-48976](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-48976)
Apache Commons FileUpload provided a hard-coded limit of 10kB for the size of the headers associated with a multipart request. A specially crafted request that used a large number of parts with large headers could trigger excessive memory usage leading to a DoS. This limit is now configurable (maxPartHeaderSize on the Connector) with a default of 512 bytes.
This was fixed with commit [74f69ffa](https://github.com/apache/tomcat/commit/74f69ffaf61e54c727603e7e831fe20f0ac5d2a7).
This issue was reported to the ASF security team on 16 May 2025. The issue was made public on 16 June 2025.
Affects: 11.0.0-M1 to 11.0.7
### 2025-05-13 Fixed in Apache Tomcat 11.0.7
**Low: CGI security constraint bypass** [CVE-2025-46701](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-46701)
When running on a case insensitive file system with security constraints configured for the `pathInfo` component of a URL that mapped to the CGI servlet, it was possible to bypass those security constraints with a specially crafted URL.
This was fixed with commits [fab7247d](https://github.com/apache/tomcat/commit/fab7247d2f0e3a29d5daef565f829f383e10e5e2) and [0f01966e](https://github.com/apache/tomcat/commit/0f01966eb60015d975525019e12a087f05ebf01a).
This issue was reported to the Tomcat security team on 7 April 2025. The issue was made public on 29 May 2025.
Affects: 11.0.0-M1 to 11.0.6
### 2025-04-09 Fixed in Apache Tomcat 11.0.6
**Low: Rewrite rule bypass** [CVE-2025-31651](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-31651)
For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed.
This was fixed with commit [fbecc915](https://github.com/apache/tomcat/commit/fbecc915a10c5a3d634c5e2c6ced4ff479ce9953).
This issue was reported to the Tomcat security team on 28 February 2025. The issue was made public on 28 April 2025.
Affects: 11.0.0-M1 to 11.0.5
**Important: Denial of Service via invalid HTTP priority header** [CVE-2025-31650](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-31650)
Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service.
This was fixed with commits [75554da2](https://github.com/apache/tomcat/commit/75554da2fc5574862510ae6f0d7b3d78937f1d40), [f619e6a0](https://github.com/apache/tomcat/commit/f619e6a05029538886d5a9d987925d573b5bb8c2) and [ded0285b](https://github.com/apache/tomcat/commit/ded0285b96b4d3f5560dfc8856ad5ec4a9b50ba9).
This issue was not disclosed responsibly. It was reported via the public bug tracker on 13 March 2025. The CVE was published on 28 April 2025.
Affects: 11.0.0-M2 to 11.0.5
### 2025-03-06 Fixed in Apache Tomcat 11.0.5
**Important: Authentication bypass with JNDIRealm and GSSAPI authenticated bind** [CVE-2026-55957](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2026-55957)
When the JNDIRealm was configured to authenticate binds using GSSAPI, an attacker was able authenticate without providing the correct password.
This was fixed with commits [fd96ab41](https://github.com/apache/tomcat/commit/fd96ab415631eea44636c94f911dd38427070ef9).
This issue was reported to the Tomcat security team on 14 June 2026. The issue was made public on 29 June 2026.
Affects: 11.0.0-M1 to 11.0.4
### 2025-02-10 Fixed in Apache Tomcat 11.0.3
**Important: Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet -** [CVE-2025-24813](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2025-24813)
The original implementation of partial PUT used a temporary file based on the user provided file name and path with the path separator replaced by ".".
If all of the following were true, a malicious user was able to view security sensitive files and/or inject content into those files:
- writes enabled for the default servlet (disabled by default)
- support for partial PUT (enabled by default)
- a target URL for security sensitive uploads that is a sub-directory of a target URL for public uploads
- attacker knowledge of the names of security sensitive files being uploaded
- the security sensitive files also being uploaded via partial PUT
If all of the following were true, a malicious user was able to perform remote code execution:
- writes enabled for the default servlet (disabled by default)
- support for partial PUT (enabled by default)
- application was using Tomcat's file based session persistence with the default storage location
- application included a library that may be leveraged in a deserialization attack
This was fixed with commit [0a668e0c](https://github.com/apache/tomcat/commit/0a668e0c27f2b7ca0cc7c6eea32253b9b5ecb29c).
This issue was reported to the Tomcat security team on 13 January 2025. The issue was made public on 10 March 2025.
Affects: 11.0.0-M1 to 11.0.2
### 2024-12-09 Fixed in Apache Tomcat 11.0.2
**Important: Remote Code Execution via write enabled Default Servlet. Mitigation for CVE-2024-50379 was incomplete -** [CVE-2024-56337](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-56337)
The previous mitigation for [CVE-2024-50379](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50379) was incomplete. In addition to upgrading to 11.0.2 or later, users running Tomcat on a case insensitive file system with the default servlet write enabled may need additional configuration depending on the version of Java being used:
- running on Java 17: the system property `sun.io.useCanonCaches`, if set, must be set to `false` (it defaults to `false`)
- running on Java 21 onwards: no further configuration is required (the system property and the problematic cache have been removed)
This issue was reported to the Tomcat security team on 17 December 2024. The issue was made public on 20 December 2024.
Affects: 11.0.0-M1 to 11.0.1
**Low: DoS in examples web application** [CVE-2024-54677](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-54677)
Numerous examples in the examples web application did not place limits on uploaded data enabling an OutOfMemoryError to be triggered causing a denial of service.
This was fixed with commits [4f023660](https://github.com/apache/tomcat/commit/4f0236606961176257b883213e1621b1859ed746), [c0a23927](https://github.com/apache/tomcat/commit/c0a23927ea5e061ca3fdff695138464179fe674a), [b1f65728](https://github.com/apache/tomcat/commit/b1f65728b37d7d227a0764344473b7e261a13408), [a95bf2b0](https://github.com/apache/tomcat/commit/a95bf2b0303442a2c9a1ac364b0e63b56049e33a), [4a335c6d](https://github.com/apache/tomcat/commit/4a335c6dcba8d6f8a54629eda392a50da267bdf4), [72281466](https://github.com/apache/tomcat/commit/722814668708c42a61b0c1e340b15bc2b785c0d1) and [cb170768](https://github.com/apache/tomcat/commit/cb1707685472994e9d924746f8c91cb116fa5213).
This issue was reported to the Tomcat security team on 23 November 2024. The issue was made public on 17 December 2024.
Affects: 11.0.0-M1 to 11.0.1
**Important: Remote Code Execution via write enabled Default Servlet** [CVE-2024-50379](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-50379)
If the default servlet is write enabled (`readonly` initialisation parameter set to the non-default value of `false`) for a case insensitive file system, concurrent read and upload under load of the same file can bypass Tomcat's case sensitivity checks and cause an uploaded file to be treated as a JSP leading to remote code execution.
This was fixed with commits [cc7a98b5](https://github.com/apache/tomcat/commit/cc7a98b57c6dc1df21979fcff94a36e068f4456c) and [684247ae](https://github.com/apache/tomcat/commit/684247ae85fa633b9197b32391de59fc54703842).
This issue was reported to the Tomcat security team on 18 October 2024. The issue was made public on 17 December 2024.
Affects: 11.0.0-M1 to 11.0.1
### 2024-11-10 Fixed in Apache Tomcat 11.0.1
**Important: XSS in generated JSPs** [CVE-2024-52318](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52318)
The fix for improvement [69333](https://bz.apache.org/bugzilla/show_bug.cgi?id=69333) caused pooled JSP tags not to be released after use which in turn could cause output of some tags not to escaped as expected. This unescaped output could lead to XSS.
This was fixed with commit [8d1fc473](https://github.com/apache/tomcat/commit/8d1fc4733a06d1a03b9d644c57010f2ec5f0df38).
This issue was not disclosed responsibly. It was reported via the public bug tracker on 6 November 2024. The CVE was published on 18 November 2024.
Affects: 11.0.0
### 2024-10-09 Fixed in Apache Tomcat 11.0.0
**Important: Request and/or response mix-up** [CVE-2024-52317](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52317)
Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users.
This was fixed with commit [9e840cca](https://github.com/apache/tomcat/commit/9e840ccacb40881c03a03b1e0746bfba7369b3bd).
This issue was identified by the Tomcat Security Team on 1 October 2024. The issue was made public on 18 November 2024.
Affects: 11.0.0-M23 to 11.0.0-M26
**Low: Authentication Bypass** [CVE-2024-52316](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-52316)
If Tomcat was configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not have failed, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way.
This was fixed with commit [6d097a66](https://github.com/apache/tomcat/commit/6d097a66746635df6880fe7662a792156b0eca14).
This issue was identified by the Tomcat Security Team on 19 September 2024. The issue was made public on 18 November 2024.
Affects: 11.0.0-M1 to 11.0.0-M26
### 2024-06-18 Fixed in Apache Tomcat 11.0.0-M21
**Important: Denial of Service** [CVE-2024-34750](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-34750)
When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed.
This was fixed with commit [2344a4c0](https://github.com/apache/tomcat/commit/2344a4c0d03e307ba6b8ab6dc8b894cc8bac63f2).
This issue was reported to the Tomcat Security Team on 4 May 2024. The issue was made public on 3 July 2024.
Affects: 11.0.0-M1 to 11.0.0-M20
**Important: Denial of Service** [CVE-2024-38286](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-38286)
Tomcat, under certain configurations on any platform, allows an attacker to cause an OutOfMemoryError by abusing the TLS handshake process.
This was fixed with commit [31978626](https://github.com/apache/tomcat/commit/3197862639732e16ec1164557bcd289ebc116c93).
This issue was reported to the Tomcat Security Team on 4 June 2024. The issue was made public on 23 September 2024.
Affects: 11.0.0-M1 to 11.0.0-M20
### 2024-02-19 Fixed in Apache Tomcat 11.0.0-M17
**Important: Denial of Service** [CVE-2024-23672](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-23672)
It was possible for a WebSocket client to keep a WebSocket connection open leading to increased resource consumption.
This was fixed with commit [b0e3b1bd](https://github.com/apache/tomcat/commit/b0e3b1bd78de270d53e319d7cb79eb282aa53cb9).
This issue was identified by the Tomcat Security Team on 17 January 2024. The issue was made public on 13 March 2024.
Affects: 11.0.0-M1 to 11.0.0-M16
**Important: Denial of Service** [CVE-2024-24549](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2024-24549)
When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.
This was fixed with commit [810f49d5](https://github.com/apache/tomcat/commit/810f49d5ff6d64b704af85d5b8d0aab9ec3c83f5).
This issue was reported to the Tomcat Security Team on 24 January 2024. The issue was made public on 13 March 2024.
Affects: 11.0.0-M1 to 11.0.0-M16
### 2023-10-10 Fixed in Apache Tomcat 11.0.0-M12
**Important: Request smuggling** [CVE-2023-45648](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-45648)
Tomcat did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy.
This was fixed with commit [eb5c094e](https://github.com/apache/tomcat/commit/eb5c094e5560764cda436362254997511a3ca1f6).
This issue was reported to the Tomcat Security Team on 12 September 2023. The issue was made public on 10 October 2023.
Affects: 11.0.0-M1 to 11.0.0-M11
**Important: Denial of Service** [CVE-2023-44487](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-44487)
Tomcat's HTTP/2 implementation was vulnerable to the rapid reset attack. The denial of service typically manifested as an `OutOfMemoryError`.
This was fixed with commit [9cdfe25b](https://github.com/apache/tomcat/commit/9cdfe25bad707f34b3e5da2994f3f1952a163c3e).
This issue was reported to the Tomcat Security Team on 14 September 2023. The issue was made public on 10 October 2023.
Affects: 11.0.0-M1 to 11.0.0-M11
**Important: Information Disclosure** [CVE-2023-42795](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-42795)
When recycling various internal objects, including the request and the response, prior to re-use by the next request/response, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/response to the next.
This was fixed with commit [d6db22e4](https://github.com/apache/tomcat/commit/d6db22e411307c97ddf78315c15d5889356eca38).
This issue was identified by the Tomcat Security Team on 13 September 2023. The issue was made public on 10 October 2023.
Affects: 11.0.0-M1 to 11.0.0-M11
### 2023-08-25 Fixed in Apache Tomcat 11.0.0-M11
**Moderate: Open redirect** [CVE-2023-41080](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-41080)
If the ROOT (default) web application is configured to use FORM authentication then it is possible that a specially crafted URL could be used to trigger a redirect to an URL of the attackers choice.
This was fixed with commit [e3703c9a](https://github.com/apache/tomcat/commit/e3703c9abb8fe0d5602f6ba8a8f11d4b6940815a).
This issue was reported to the Tomcat Security Team on 17 August 2023. The issue was made public on 22 August 2023.
Affects: 11.0.0-M1 to 11.0.0-M10
**Important: Request smuggling** [CVE-2023-46589](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-46589)
Tomcat did not correctly parse HTTP trailer headers. A specially crafted trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy.
This was fixed with commit [6f181e10](https://github.com/apache/tomcat/commit/6f181e1062a472bc5f0234980f66cbde42c1041b).
This issue was reported to the Tomcat Security Team on 20 October 2023. The issue was made public on 28 November 2023.
Affects: 11.0.0-M1 to 11.0.0-M10
### 2023-05-09 Fixed in Apache Tomcat 11.0.0-M6
**Important: Information disclosure** [CVE-2023-34981](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34981)
The fix for bug [66512](https://bz.apache.org/bugzilla/show_bug.cgi?id=66512) introduced a regression that was fixed as bug [66591](https://bz.apache.org/bugzilla/show_bug.cgi?id=66591). The regression meant that, if a response did not have any HTTP headers set, no AJP `SEND_HEADERS` message would be sent which in turn meant that at least one AJP based proxy (mod\_proxy\_ajp) would use the response headers from the previous request for the current request leading to an information leak.
This was fixed with commit [739c7381](https://github.com/apache/tomcat/commit/739c7381aed22b7636351caf885ddc519ab6b442).
This issue was reported to the Tomcat Security Team on 24 May 2023. The issue was made public on 21 June 2023.
Affects: 11.0.0-M5
### 2023-04-19 Fixed in Apache Tomcat 11.0.0-M5
**Moderate: Apache Tomcat denial of service** [CVE-2023-28709](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28709)
The fix for [CVE-2023-24998](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24998) was incomplete. If non-default HTTP connector settings were used such that the `maxParameterCount` could be reached using query string parameters and a request was submitted that supplied exactly `maxParameterCount` parameters in the query string, the limit for uploaded request parts could be bypassed with the potential for a denial of service to occur.
This was fixed with commit [d53d8e7f](https://github.com/apache/tomcat/commit/d53d8e7f77042cc32a3b98f589496a1ef5088e38).
This issue was reported to the Tomcat Security Team on 13 March 2023. The issue was made public on 22 May 2023.
Affects: 11.0.0-M2 to 11.0.0-M4
### 2023-02-23 Fixed in Apache Tomcat 11.0.0-M3
**Important: Apache Tomcat information disclosure** [CVE-2023-28708](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-28708)
When using the `RemoteIpFilter` with requests received from a reverse proxy via HTTP that include the `X-Forwarded-Proto` header set to `https`, session cookies created by Tomcat did not include the secure attribute. This could result in the user agent transmitting the session cookie over an insecure channel.
This was fixed with commit [c64d496d](https://github.com/apache/tomcat/commit/c64d496dda1560b5df113be55fbfaefec349b50f).
[66471](https://bz.apache.org/bugzilla/show_bug.cgi?id=66471) was reported publicly on 8 February 2023. The security implications were identified by the Tomcat Security team on 9 February 2023. The issue was made public on 22 March 2023.
Affects: 11.0.0-M1 to 11.0.0-M2
*Note: The issue below was fixed in Apache Tomcat 11.0.0-M2 but the release vote for the 11.0.0-M2 release candidate did not pass. Therefore, although users must download 11.0.0-M3 to obtain a version that includes a fix for these issues, version 11.0.0-M2 is not included in the list of affected versions.*
**Important: Apache Tomcat denial of service** [CVE-2023-24998](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24998)
Apache Tomcat uses a packaged renamed copy of Apache Commons FileUpload to provide the file upload functionality defined in the Jakarta Servlet specification. Apache Tomcat was, therefore, also vulnerable to the Apache Commons FileUpload vulnerability [CVE-2023-24998](http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-24998) as there was no limit to the number of request parts processed. This resulted in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.
This was fixed with commit [063e2e81](https://github.com/apache/tomcat/commit/063e2e81ede50c287f737cc8e2915ce7217e886e).
This issue was reported to the Apache Tomcat Security team on 11 December 2022. The issue was made public on 20 February 2023.
Affects: 11.0.0-M1