GHSA-69cc-cv78-qc8gHighCVSS 7.5

Apache Tomcat: Configured cipher preference order not preserved

Published
April 9, 2026
Last Modified
May 20, 2026

🔗 CVE IDs covered (1)

📋 Description

Configured cipher preference order not preserved vulnerability in Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115.

Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

🎯 Affected products9

  • maven/org.apache.tomcat:tomcat:>= 9.0.114, < 9.0.116
  • maven/org.apache.tomcat:tomcat:>= 10.1.51, < 10.1.53
  • maven/org.apache.tomcat:tomcat:>= 11.0.16, < 11.0.20
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 9.0.114, < 9.0.116
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 10.1.51, < 10.1.53
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 11.0.16, < 11.0.20
  • maven/org.apache.tomcat:tomcat-coyote:>= 9.0.114, < 9.0.116
  • maven/org.apache.tomcat:tomcat-coyote:>= 10.1.51, < 10.1.53
  • maven/org.apache.tomcat:tomcat-coyote:>= 11.0.16, < 11.0.20

🔗 References (10)