Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-43512

Apache Tomcat: DIGEST authenticator authenticates unknown users who send the password "null"

Technology

Apache Tomcat

CVSS Score

9.8 / 10.0

Affected Versions

11.0.0-M1 to 11.0.21; 10.1.0-M1 to 10.1.54; 9.0.0.M1 to 9.0.117; end of life but named in the record: 8.5.0 to 8.5.100, 7.0.0 to 7.0.109

Upstream Fix

11.0.22; 10.1.55; 9.0.118

Published

May 12, 2026

OSSeva Coverage

Fixed upstream

Description

With DIGEST authentication configured, any user not known to the configured Realm was authenticated if they presented the password "null". Rated Moderate by the Tomcat security team; CISA-ADP scores it 9.8. Fixed in 11.0.22, 10.1.55 and 9.0.118.

Upstream record: NVD · CVE.org

Is your Apache Tomcat deployment affected?

If you're running 11.0.0-M1 to 11.0.21; 10.1.0-M1 to 10.1.54; 9.0.0.M1 to 9.0.117; end of life but named in the record: 8.5.0 to 8.5.100, 7.0.0 to 7.0.109, you need this patch. Book a discovery call to get covered.