Back to Vulnerability Directory
CRITICALFixed upstream
CVE-2026-43512
Apache Tomcat: DIGEST authenticator authenticates unknown users who send the password "null"
Technology
Apache Tomcat
CVSS Score
9.8 / 10.0
Affected Versions
11.0.0-M1 to 11.0.21; 10.1.0-M1 to 10.1.54; 9.0.0.M1 to 9.0.117; end of life but named in the record: 8.5.0 to 8.5.100, 7.0.0 to 7.0.109
Upstream Fix
11.0.22; 10.1.55; 9.0.118
Published
May 12, 2026
OSSeva Coverage
Fixed upstream
Is your Apache Tomcat deployment affected?
If you're running 11.0.0-M1 to 11.0.21; 10.1.0-M1 to 10.1.54; 9.0.0.M1 to 9.0.117; end of life but named in the record: 8.5.0 to 8.5.100, 7.0.0 to 7.0.109, you need this patch. Book a discovery call to get covered.