ニュース
「Apache Tomcat」に重要な脆弱性 ~セキュリティ制約をバイパスされるなどの恐れ
v9 / v10 / v11系統に影響、全10件の問題を修正
2026年8月26日 19:50
脆弱性対策情報ポータルサイト「JVN」は8月26日、「Apache Tomcat」に10件の脆弱性が存在することを明らかにした。9 / v10 / v11系統に影響し、最大深刻度はThe Apache Software Foundationの基準で4段階中2番目に高いImportant。
いずれの脆弱性も「Apache Tomcat」のv9.0.121 / v10.1.59 / v11.0.25にアップデート、またはサンプルWebアプリケーションを削除することで対処できる。各脆弱性のCVE番号と深刻度、サポート継続中バージョンの影響範囲は以下の通り。
○CVE-2026-65182:Security constraint bypass(Important)
- Apache Tomcat 11.0.0-M1 to 11.0.24
- Apache Tomcat 10.1.0-M1 to 10.1.57
- Apache Tomcat 9.0.0.M1 to 9.0.120
○CVE-2026-65183:TOCTOU when setting specific permissions for Unix Domain Sockets
(Low)
- Apache Tomcat 11.0.0-M1 to 11.0.24
- Apache Tomcat 10.1.0-M1 to 10.1.57
- Apache Tomcat 9.0.42 to 9.0.120
○CVE-2026-65637:HTTP/2 no-authority bypass of strict SNI validation(Moderate)
- Apache Tomcat 11.0.20 to 11.0.24
- Apache Tomcat 10.1.53 to 10.1.57
- Apache Tomcat 9.0.115 to 9.0.120
○CVE-2026-65927:RewriteValve [N] restarts at the second rule and may bypass access control(Important)
- Apache Tomcat 11.0.0-M1 to 11.0.24
- Apache Tomcat 10.1.0-M1 to 10.1.57
- Apache Tomcat 9.0.0.M1 to 9.0.120
○CVE-2026-65905:Limited replay attack possible with
DIGEST authentication(Low)
- Apache Tomcat 11.0.0-M1 to 11.0.24
- Apache Tomcat 10.1.0-M1 to 10.1.57
- Apache Tomcat 9.0.0.M1 to 9.0.120
○CVE-2026-66422:Servlet role references can bypass declarative role constraints(Low)
- Apache Tomcat 11.0.0-M1 to 11.0.24
- Apache Tomcat 10.1.0-M1 to 10.1.57
- Apache Tomcat 9.0.25 to 9.0.120
○CVE-2026-68525:Redirect after FORM authentication may bypass method specific constraints(Low)
- Apache Tomcat 11.0.0-M1 to 11.0.24
- Apache Tomcat 10.1.0-M1 to 10.1.57
- Apache Tomcat 9.0.0.M1 to 9.0.120
○CVE-2026-73180:Authenticated WebSocket session survives end of HTTP session(Low)
- Apache Tomcat 11.0.0-M1 to 11.0.24
- Apache Tomcat 10.1.0-M1 to 10.1.57
- Apache Tomcat 9.0.0.M1 to 9.0.120
○CVE-2026-68569:Principal lookup can fail open in some cases(Important)
- Apache Tomcat 11.0.0-M1 to 11.0.24
- Apache Tomcat 10.1.0-M1 to 10.1.57
- Apache Tomcat 9.0.0.M1 to 9.0.120
○CVE-2026-68763:DoS via allocation leak in HTTP/2 backlog
tracking when a stream is reset(Important)
- Apache Tomcat 11.0.0-M1 to 11.0.24
- Apache Tomcat 10.1.0-M1 to 10.1.57
- Apache Tomcat 9.0.39 to 9.0.120





















