Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5376 articles · 221061 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-65905PATCHED
apache · tomcat

Apache Tomcat: Limited replay attack possible with DIGEST authentication

Description

Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that request is replayable once only while the associated nonceCount remains within the replay window.   This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

Affected Products

VendorProductVersions
apachetomcatmaven/org.apache.tomcat:tomcat: >= 11.0.0-M1, < 11.0.25, maven/org.apache.tomcat:tomcat: >= 10.1.0-M1, < 10.1.58, maven/org.apache.tomcat:tomcat: >= 9.0.0.M1, < 9.0.121, maven/org.apache.tomcat:tomcat: >= 8.5.0, <= 8.5.100, maven/org.apache.tomcat:tomcat: >= 7.0.30, <= 7.0.109, maven/org.apache.tomcat.embed:tomcat-embed-core: >= 11.0.0-M1, < 11.0.25, maven/org.apache.tomcat.embed:tomcat-embed-core: >= 10.1.0-M1, < 10.1.58, maven/org.apache.tomcat.embed:tomcat-embed-core: >= 9.0.0.M1, < 9.0.121, maven/org.apache.tomcat.embed:tomcat-embed-core: >= 8.5.0, <= 8.5.100, maven/org.apache.tomcat.embed:tomcat-embed-core: >= 7.0.30, <= 7.0.109, maven/org.apache.tomcat:tomcat-catalina: >= 11.0.0-M1, < 11.0.25, maven/org.apache.tomcat:tomcat-catalina: >= 10.1.0-M1, < 10.1.58, maven/org.apache.tomcat:tomcat-catalina: >= 9.0.0.M1, < 9.0.121, maven/org.apache.tomcat:tomcat-catalina: >= 8.5.0, <= 8.5.100, maven/org.apache.tomcat:tomcat-catalina: >= 7.0.30, <= 7.0.109

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apachetomcatcert_advisory90%
mavenorg.apache.tomcat:tomcatGHSA85%
mavenorg.apache.tomcat.embed:tomcat-embed-coreGHSA85%
mavenorg.apache.tomcat:tomcat-catalinaGHSA85%

References

  • https://lists.apache.org/thread/9v114xlpgbzrrbzz5vf9f6r2q4wnxwwj(vendor-advisory)

Related News (5 articles)

Tier B
CERT-FR11d ago
Multiples vulnérabilités dans les produits IBM (11 septembre 2026)
→ No new info (linked only)
Tier B
BSI Advisories27d ago
[NEU] [hoch] Apache Tomcat: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
oss-security27d ago
CVE-2026-65905: Apache Tomcat: Limited replay attack possible with DIGEST authentication
→ No new info (linked only)
Tier B
CERT-FR27d ago
Multiples vulnérabilités dans Apache Tomcat (26 août 2026)
→ No new info (linked only)
Tier C
VulDB27d ago
CVE-2026-65905 | Apache Tomcat up to 11.0.24 DIGEST Authenticator authentication replay
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
Patch available
org.apache.tomcat:tomcat@11.0.25org.apache.tomcat:tomcat@10.1.58org.apache.tomcat:tomcat@9.0.121org.apache.tomcat.embed:tomcat-embed-core@11.0.25org.apache.tomcat.embed:tomcat-embed-core@10.1.58org.apache.tomcat.embed:tomcat-embed-core@9.0.121org.apache.tomcat:tomcat-catalina@11.0.25org.apache.tomcat:tomcat-catalina@10.1.58org.apache.tomcat:tomcat-catalina@9.0.121
CWECWE-294
PublishedAug 25, 2026
Trending Score18
Source articles5
Independent4
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-59084EXP
Apache Tomcat: EncryptInterceptor requirements not clearly documented
Trending: 42
CRITICALCVE-2026-59083EXP
Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass
Trending: 42
CRITICALCVE-2026-66713
Apache Axis2/Java: deserialization of untrusted Data
Trending: 37
HIGHCVE-2026-50734
Apache ActiveMQ Client, Apache ActiveMQ, Apache ActiveMQ All: Pre-authentication OpenWire memory-allocation DoS during wire format negotiation
Trending: 34
HIGHCVE-2026-64958
Apache CXF: Denial of service via message header attachments
Trending: 34

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 25, 2026
Discovered by ZDM
Aug 25, 2026
Patch Available
Aug 26, 2026