CVE-2026-34483
published 2026-04-09CVE-2026-34483: Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1…
PriorityP349high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.46%
37.1th percentile
Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | >= 10.1.0 < 10.1.54 | 10.1.54 |
| apache | tomcat | >= 11.0.0 < 11.0.21 | 11.0.21 |
| apache | tomcat | >= 9.0.40 < 9.0.117 | 9.0.117 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.53 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.20 | — |
| apache_software_foundation | apache_tomcat | 8.5.84 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.40 – 9.0.116 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
ghsa·2026-04-09
CVE-2026-34483 [HIGH] CWE-116 Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve
Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.
GHSA
GHSA-rv64-5gf8-9qq8: Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat
ghsa_unreviewed·2026-04-09
CVE-2026-34483 CWE-116 GHSA-rv64-5gf8-9qq8: Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat
Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.
VulDB
Apache Tomcat up to 8.5.82/8.5.100/9.0.116/10.1.53/11.0.20 JsonAccessLogValve escape output
vuldb·2026-04-09·CVSS 7.5
CVE-2026-34483 [HIGH] Apache Tomcat up to 8.5.82/8.5.100/9.0.116/10.1.53/11.0.20 JsonAccessLogValve escape output
A vulnerability described as problematic has been identified in Apache Tomcat up to 8.5.82/8.5.100/9.0.116/10.1.53/11.0.20. Affected by this issue is some unknown functionality of the component JsonAccessLogValve. The manipulation results in escaping of output.
This vulnerability is identified as CVE-2026-34483. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is recommended.
Red Hat
Apache Tomcat: Apache Tomcat: Information disclosure due to improper encoding in JsonAccessLogValve
vendor_redhat·2026-04-09·CVSS 7.5
CVE-2026-34483 [HIGH] CWE-838 Apache Tomcat: Apache Tomcat: Information disclosure due to improper encoding in JsonAccessLogValve
Apache Tomcat: Apache Tomcat: Information disclosure due to improper encoding in JsonAccessLogValve
A flaw was found in the JsonAccessLogValve component of Apache Tomcat. This improper encoding or escaping of output vulnerability could allow an attacker to inject specially crafted data into log files. This could lead to information disclosure or other unintended consequences when the logs are processed or viewed.
Statement: Low impact. A flaw in the Apache Tomcat JsonAccessLogValve component allows for improper encoding of output. This could enable an attacker to inject specially crafted data into log files, potentially leading to information disclosure or other unintended consequences during log processing. This affects Red Hat Enterprise Linux versions 6, 7, 8, 9, and 10.
Mitigation:
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-34483 tomcat: Apache Tomcat: Information disclosure due to improper encoding in JsonAccessLogValve [fedora-all]
bugzilla·2026-04-10·CVSS 7.5
CVE-2026-34483 [HIGH] CVE-2026-34483 tomcat: Apache Tomcat: Information disclosure due to improper encoding in JsonAccessLogValve [fedora-all]
CVE-2026-34483 tomcat: Apache Tomcat: Information disclosure due to improper encoding in JsonAccessLogValve [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-34483 Apache Tomcat: Apache Tomcat: Information disclosure due to improper encoding in JsonAccessLogValve
bugzilla·2026-04-09·CVSS 7.5
CVE-2026-34483 [HIGH] CVE-2026-34483 Apache Tomcat: Apache Tomcat: Information disclosure due to improper encoding in JsonAccessLogValve
CVE-2026-34483 Apache Tomcat: Apache Tomcat: Information disclosure due to improper encoding in JsonAccessLogValve
Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.
2026-04-09
Published