ニュース

「Apache Tomcat」に重要な脆弱性 ~セキュリティ制約をバイパスされるなどの恐れ

v9 / v10 / v11系統に影響、全10件の問題を修正

「Apache Tomcat」に重大な脆弱性

 脆弱性対策情報ポータルサイト「JVN」は8月26日、「Apache Tomcat」に10件の脆弱性が存在することを明らかにした。9 / v10 / v11系統に影響し、最大深刻度はThe Apache Software Foundationの基準で4段階中2番目に高いImportant。

 いずれの脆弱性も「Apache Tomcat」のv9.0.121 / v10.1.59 / v11.0.25にアップデート、またはサンプルWebアプリケーションを削除することで対処できる。各脆弱性のCVE番号と深刻度、サポート継続中バージョンの影響範囲は以下の通り。

CVE-2026-65182:Security constraint bypass(Important)

  • Apache Tomcat 11.0.0-M1 to 11.0.24
  • Apache Tomcat 10.1.0-M1 to 10.1.57
  • Apache Tomcat 9.0.0.M1 to 9.0.120

CVE-2026-65183:TOCTOU when setting specific permissions for Unix Domain Sockets

(Low)

  • Apache Tomcat 11.0.0-M1 to 11.0.24
  • Apache Tomcat 10.1.0-M1 to 10.1.57
  • Apache Tomcat 9.0.42 to 9.0.120

CVE-2026-65637:HTTP/2 no-authority bypass of strict SNI validation(Moderate)

  • Apache Tomcat 11.0.20 to 11.0.24
  • Apache Tomcat 10.1.53 to 10.1.57
  • Apache Tomcat 9.0.115 to 9.0.120

CVE-2026-65927:RewriteValve [N] restarts at the second rule and may bypass access control(Important)

  • Apache Tomcat 11.0.0-M1 to 11.0.24
  • Apache Tomcat 10.1.0-M1 to 10.1.57
  • Apache Tomcat 9.0.0.M1 to 9.0.120

CVE-2026-65905:Limited replay attack possible with

DIGEST authentication(Low)

  • Apache Tomcat 11.0.0-M1 to 11.0.24
  • Apache Tomcat 10.1.0-M1 to 10.1.57
  • Apache Tomcat 9.0.0.M1 to 9.0.120

CVE-2026-66422:Servlet role references can bypass declarative role constraints(Low)

  • Apache Tomcat 11.0.0-M1 to 11.0.24
  • Apache Tomcat 10.1.0-M1 to 10.1.57
  • Apache Tomcat 9.0.25 to 9.0.120

CVE-2026-68525:Redirect after FORM authentication may bypass method specific constraints(Low)

  • Apache Tomcat 11.0.0-M1 to 11.0.24
  • Apache Tomcat 10.1.0-M1 to 10.1.57
  • Apache Tomcat 9.0.0.M1 to 9.0.120

CVE-2026-73180:Authenticated WebSocket session survives end of HTTP session(Low)

  • Apache Tomcat 11.0.0-M1 to 11.0.24
  • Apache Tomcat 10.1.0-M1 to 10.1.57
  • Apache Tomcat 9.0.0.M1 to 9.0.120

CVE-2026-68569:Principal lookup can fail open in some cases(Important)

  • Apache Tomcat 11.0.0-M1 to 11.0.24
  • Apache Tomcat 10.1.0-M1 to 10.1.57
  • Apache Tomcat 9.0.0.M1 to 9.0.120

CVE-2026-68763:DoS via allocation leak in HTTP/2 backlog

tracking when a stream is reset(Important)

  • Apache Tomcat 11.0.0-M1 to 11.0.24
  • Apache Tomcat 10.1.0-M1 to 10.1.57
  • Apache Tomcat 9.0.39 to 9.0.120