CVE-2026-76183
Apache Tomcat: security constraints for WebSocket endpoints can be bypassed
Technology
Apache Tomcat
CVSS Score
9.8 / 10.0
Affected Versions
11.0.0-M1 to 11.0.25; 10.1.0-M1 to 10.1.59; 9.0.0.M1 to 9.0.121; end of support but known affected: 8.5.0 to 8.5.100, 7.0.43 to 7.0.109
Upstream Fix
11.0.26; 10.1.60; 9.0.122
Published
September 23, 2026
OSSeva Coverage
Fixed upstream
Description
Tomcat parsed request paths as WebSocket endpoint templates, which allowed the security constraints for any WebSocket endpoint to be bypassed (authentication bypass by alternate name). Made public on 23 September 2026 and rated Important by the Tomcat security team. The advisory lists 8.5.0 to 8.5.100 and 7.0.43 to 7.0.109 as affected; both lines are end of support. Fixed in 11.0.26, 10.1.60 and 9.0.122.
Is your Apache Tomcat deployment affected?
If you're running 11.0.0-M1 to 11.0.25; 10.1.0-M1 to 10.1.59; 9.0.0.M1 to 9.0.121; end of support but known affected: 8.5.0 to 8.5.100, 7.0.43 to 7.0.109, you need this patch. Book a discovery call to get covered.