Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2026-76183

Apache Tomcat: security constraints for WebSocket endpoints can be bypassed

Technology

Apache Tomcat

CVSS Score

9.8 / 10.0

Affected Versions

11.0.0-M1 to 11.0.25; 10.1.0-M1 to 10.1.59; 9.0.0.M1 to 9.0.121; end of support but known affected: 8.5.0 to 8.5.100, 7.0.43 to 7.0.109

Upstream Fix

11.0.26; 10.1.60; 9.0.122

Published

September 23, 2026

OSSeva Coverage

Fixed upstream

Description

Tomcat parsed request paths as WebSocket endpoint templates, which allowed the security constraints for any WebSocket endpoint to be bypassed (authentication bypass by alternate name). Made public on 23 September 2026 and rated Important by the Tomcat security team. The advisory lists 8.5.0 to 8.5.100 and 7.0.43 to 7.0.109 as affected; both lines are end of support. Fixed in 11.0.26, 10.1.60 and 9.0.122.

Upstream record: NVD · CVE.org

Is your Apache Tomcat deployment affected?

If you're running 11.0.0-M1 to 11.0.25; 10.1.0-M1 to 10.1.59; 9.0.0.M1 to 9.0.121; end of support but known affected: 8.5.0 to 8.5.100, 7.0.43 to 7.0.109, you need this patch. Book a discovery call to get covered.