Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-43515

Apache Tomcat: security constraints not correctly applied for repeated extension patterns

Technology

Apache Tomcat

CVSS Score

9.1 / 10.0

Affected Versions

11.0.0-M1 to 11.0.21; 10.1.0-M1 to 10.1.54; 9.0.0.M1 to 9.0.117; end of life but named in the record: 8.5.0 to 8.5.100, 7.0.0 to 7.0.109

Upstream Fix

11.0.22; 10.1.55; 9.0.118

Published

May 12, 2026

OSSeva Coverage

Fixed upstream

Description

When multiple security constraints defined an HTTP method constraint for the same extension pattern, only the first method constraint was applied, so requests that the other constraints should have restricted could get through. Rated Moderate by the Tomcat security team; CISA-ADP scores it 9.1. Fixed in 11.0.22, 10.1.55 and 9.0.118.

Upstream record: NVD · CVE.org

Is your Apache Tomcat deployment affected?

If you're running 11.0.0-M1 to 11.0.21; 10.1.0-M1 to 10.1.54; 9.0.0.M1 to 9.0.117; end of life but named in the record: 8.5.0 to 8.5.100, 7.0.0 to 7.0.109, you need this patch. Book a discovery call to get covered.