GHSA-fv25-8xcx-gqjcHighCVSS 7.3

Apache Tomcat - WebSocket authentication header exposure

Published
May 12, 2026
Last Modified
May 18, 2026

🔗 CVE IDs covered (1)

📋 Description

Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.21 Apache Tomcat 10.1.0-M1 to 10.1.54 Apache Tomcat 9.0.2 to 9.0.117 Older, unsupported versions may also be affected

Description: If a WebSocket request was redirected after authentication, Tomcat's WebSocket client would present the most recent authentication header to the redirect target host.

Mitigation: Users of the affected versions should apply one of the following mitigations:

  • Upgrade to Apache Tomcat 11.0.22 or later
  • Upgrade to Apache Tomcat 10.1.55 or later
  • Upgrade to Apache Tomcat 9.0.118 or later

Credit: This issue was identified by lokerxx

🎯 Affected products9

  • maven/org.apache.tomcat.embed:tomcat-embed-core:< 9.0.118
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 10.1.0-M1, < 10.1.55
  • maven/org.apache.tomcat.embed:tomcat-embed-core:>= 11.0.0-M1, < 11.0.22
  • maven/org.apache.tomcat:tomcat:< 9.0.118
  • maven/org.apache.tomcat:tomcat:>= 10.1.0-M1, < 10.1.55
  • maven/org.apache.tomcat:tomcat:>= 11.0.0-M1, < 11.0.22
  • maven/org.apache.tomcat:tomcat-catalina:< 9.0.118
  • maven/org.apache.tomcat:tomcat-catalina:>= 10.1.0-M1, < 10.1.55
  • maven/org.apache.tomcat:tomcat-catalina:>= 11.0.0-M1, < 11.0.22

🔗 References (10)