CVE-2026-43515
Apache Tomcat: security constraints not correctly applied for repeated extension patterns
Technology
Apache Tomcat
CVSS Score
9.1 / 10.0
Affected Versions
11.0.0-M1 to 11.0.21; 10.1.0-M1 to 10.1.54; 9.0.0.M1 to 9.0.117; end of life but named in the record: 8.5.0 to 8.5.100, 7.0.0 to 7.0.109
Upstream Fix
11.0.22; 10.1.55; 9.0.118
Published
May 12, 2026
OSSeva Coverage
Fixed upstream
Description
When multiple security constraints defined an HTTP method constraint for the same extension pattern, only the first method constraint was applied, so requests that the other constraints should have restricted could get through. Rated Moderate by the Tomcat security team; CISA-ADP scores it 9.1. Fixed in 11.0.22, 10.1.55 and 9.0.118.
Is your Apache Tomcat deployment affected?
If you're running 11.0.0-M1 to 11.0.21; 10.1.0-M1 to 10.1.54; 9.0.0.M1 to 9.0.117; end of life but named in the record: 8.5.0 to 8.5.100, 7.0.0 to 7.0.109, you need this patch. Book a discovery call to get covered.