Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4391 articles · 196851 vulns · 37/41 feeds (7d)
← Back to list
7.3
CVE-2026-42498EXPLOITEDPATCHED
apache · tomcat

Apache Tomcat: WebSocket authentication header exposure

Description

Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.

Affected Products

VendorProductVersions
apachetomcatmaven/org.apache.tomcat.embed:tomcat-embed-core: < 9.0.118, maven/org.apache.tomcat.embed:tomcat-embed-core: >= 10.1.0-M1, < 10.1.55, maven/org.apache.tomcat.embed:tomcat-embed-core: >= 11.0.0-M1, < 11.0.22, maven/org.apache.tomcat:tomcat: < 9.0.118, maven/org.apache.tomcat:tomcat: >= 10.1.0-M1, < 10.1.55, maven/org.apache.tomcat:tomcat: >= 11.0.0-M1, < 11.0.22, maven/org.apache.tomcat:tomcat-catalina: < 9.0.118, maven/org.apache.tomcat:tomcat-catalina: >= 10.1.0-M1, < 10.1.55, maven/org.apache.tomcat:tomcat-catalina: >= 11.0.0-M1, < 11.0.22

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
atlassiancruciblecert_advisory90%
atlassianfisheyecert_advisory90%
atlassianbitbucketcert_advisory90%
atlassianjiracert_advisory90%
atlassianconfluencecert_advisory90%

References

  • https://lists.apache.org/thread/n61zwf75jrv09rz90j4jssncm244bwdb(vendor-advisory)

Related News (7 articles)

Tier B
CERT-FR18d ago
Multiples vulnérabilités dans les produits IBM (07 août 2026)
→ No new info (linked only)
Tier B
BSI Advisories34d ago
[NEU] [hoch] Oracle Solaris Drittanbieterkomponenten: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR68d ago
Multiples vulnérabilités dans les produits Atlassian (18 juin 2026)
→ No new info (linked only)
Tier B
BSI Advisories69d ago
[NEU] [hoch] Atlassian Bamboo, Bitbucket, Confluence, Fisheye, Crucible, Jira und Jira Service Management: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR104d ago
Multiples vulnérabilités dans Apache Tomcat (13 mai 2026)
→ No new info (linked only)
Tier C
VulDB104d ago
CVE-2026-42498 | Apache Tomcat up to 11.0.21 WebSocket Authentication information disclosure
→ No new info (linked only)
Tier C
oss-security104d ago
CVE-2026-42498: Apache Tomcat: WebSocket authentication header exposure
→ No new info (linked only)
CVSS 3.17.3 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA KEV❌ No
Actively exploited✅ Yes
Patch available
org.apache.tomcat.embed:tomcat-embed-core@9.0.118org.apache.tomcat.embed:tomcat-embed-core@10.1.55org.apache.tomcat.embed:tomcat-embed-core@11.0.22org.apache.tomcat:tomcat@9.0.118org.apache.tomcat:tomcat@10.1.55org.apache.tomcat:tomcat@11.0.22org.apache.tomcat:tomcat-catalina@9.0.118org.apache.tomcat:tomcat-catalina@10.1.55org.apache.tomcat:tomcat-catalina@11.0.22
CWECWE-200
PublishedMay 12, 2026
Last enriched104d agov3
Tags
CVE-2026-42498
Trending Score5
Source articles7
Independent4
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

NONECVE-2026-53434EXP
Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector
Trending: 40
HIGHCVE-2026-57819
Apache CXF: No default restriction on the amount of form parameters per message
Trending: 34
CRITICALCVE-2026-59084EXP
Apache Tomcat: EncryptInterceptor requirements not clearly documented
Trending: 34
HIGHCVE-2026-54225
Apache CXF: Denial of Service attack via large attachments
Trending: 34
HIGHCVE-2026-64958
Apache CXF: Denial of service via message header attachments
Trending: 34

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 12, 2026
Discovered by ZDM
May 12, 2026
Updated: severity
May 12, 2026
Updated: severity, activelyExploited, tags
May 12, 2026
Actively Exploited
May 13, 2026
Patch Available
May 13, 2026

Version History

v3
Last enriched 104d ago
v3Tier C104d ago

Updated severity to MEDIUM, marked as actively exploited, and added CVE ID CVE-2026-42498.

severityactivelyExploitedtags
via VulDB
v2Tier C104d ago

Updated severity from NONE to LOW and set patchAvailable to null.

severity
via oss-security
v1104d ago

Initial creation