CVE-2026-43515

CVE-2026-43515: Apache Tomcat: Security constraints not correctly applied

Vendor Apache Software Foundation
Product Apache Tomcat
Weakness CWE-285
Published May 12, 2026
Last update June 4, 2026

CVSS base score

What the vulnerability does

Description

Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

Key dates

Disclosure timeline

May 12, 2026 CVE published
June 4, 2026 Record updated