CVE-2026-42498
published 2026-05-12CVE-2026-42498: Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat…
PriorityP350high7.3CVSS 3.1
AVNACLPRNUINSUCLILAL
EPSS
0.55%
42.6th percentile
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | >= 10.1.0 < 10.1.55 | 10.1.55 |
| apache | tomcat | >= 11.0.0 < 11.0.22 | 11.0.22 |
| apache | tomcat | 7.0.0 – 7.0.109 | — |
| apache | tomcat | 8.5.0 – 8.5.100 | — |
| apache | tomcat | >= 9.0.0 < 9.0.118 | 9.0.118 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.54 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.21 | — |
| apache_software_foundation | apache_tomcat | 7.0.83 – 7.0.109 | — |
| apache_software_foundation | apache_tomcat | 8.5.24 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.2 – 9.0.117 | — |
| debian | jss | — | — |
| debian | tomcat10 | — | — |
| debian | tomcat11 | — | — |
| devspaces | server-rhel9 | — | — |
| redhat-pki_10 | jss | — | — |
| ubuntu | tomcat10 | — | — |
| ubuntu | tomcat11 | — | — |
| ubuntu | tomcat9 | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
vendor_ubuntu7.5HIGH
vendor_redhat7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2026-06-18·CVSS 7.5
CVE-2026-42498 [HIGH] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat did not properly limit the size of
WebDAV LOCK and PROPFIND request bodies. A remote attacker could
possibly use this issue to cause Tomcat to consume excessive memory,
resulting in a denial of service. (CVE-2026-41284)
It was discovered that Tomcat incorrectly validated HTTP/2 header
fields. A remote attacker could use this issue to cause Tomcat to
crash or possibly execute arbitrary code. (CVE-2026-41293)
It was discovered that Tomcat did not properly clear HTTP
authentication headers during WebSocket connection upgrades and
redirects. A remote attacker could possibly use this issue to obtain
sensitive credentials. (CVE-2026-42498)
It was discovered that Tomcat incorrec
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2026-06-10·CVSS 7.5
CVE-2026-41284 [HIGH] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat did not properly limit the size of
WebDAV LOCK and PROPFIND request bodies. A remote attacker could
use this issue to cause Tomcat to consume excessive memory,
resulting in a denial of service. (CVE-2026-41284)
It was discovered that Tomcat incorrectly validated HTTP/2 header
fields. A remote attacker could use this issue to cause Tomcat to
crash or possibly execute arbitrary code. (CVE-2026-41293)
It was discovered that Tomcat did not properly clear HTTP
authentication headers during WebSocket connection upgrades and
redirects. A remote attacker could use this issue to obtain
sensitive credentials. (CVE-2026-42498)
It was discovered that Tomcat incorrectly handled digest
Red Hat
tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication.
vendor_redhat·2026-05-12·CVSS 7.3
CVE-2026-42498 [HIGH] CWE-201 tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication.
tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication.
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.
A flaw was found in Apache Tomcat. During WebSocket authentication, the HTTP Authentication Header can be exposed to unexpected hosts. This vulnerability leads to information disclosure, potentially allowing an attacker to gain access to sensitive authentication crede
GHSA
GHSA-fv25-8xcx-gqjc: Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat
ghsa_unreviewed·2026-05-12
CVE-2026-42498 [HIGH] CWE-200 GHSA-fv25-8xcx-gqjc: Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.
GHSA
Apache Tomcat - WebSocket authentication header exposure
ghsa·2026-05-12
CVE-2026-42498 [HIGH] CWE-200 Apache Tomcat - WebSocket authentication header exposure
Apache Tomcat - WebSocket authentication header exposure
Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.21
Apache Tomcat 10.1.0-M1 to 10.1.54
Apache Tomcat 9.0.2 to 9.0.117
Older, unsupported versions may also be affected
Description:
If a WebSocket request was redirected after authentication, Tomcat's
WebSocket client would present the most recent authentication header to
the redirect target host.
Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Apache Tomcat 11.0.22 or later
- Upgrade to Apache Tomcat 10.1.55 or later
- Upgrade to Apache Tomcat 9.0.118 or later
Credit:
This issue was identified by lokerxx
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-42498 mod_cluster: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. [fedora-all]
bugzilla·2026-06-12·CVSS 7.3
CVE-2026-42498 [HIGH] CVE-2026-42498 mod_cluster: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. [fedora-all]
CVE-2026-42498 mod_cluster: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-42498 mod_proxy_cluster: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. [fedora-all]
bugzilla·2026-06-12·CVSS 7.3
CVE-2026-42498 [HIGH] CVE-2026-42498 mod_proxy_cluster: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. [fedora-all]
CVE-2026-42498 mod_proxy_cluster: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-42498 jss: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. [fedora-all]
bugzilla·2026-06-12·CVSS 7.3
CVE-2026-42498 [HIGH] CVE-2026-42498 jss: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. [fedora-all]
CVE-2026-42498 jss: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication. [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-42498 tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication.
bugzilla·2026-05-12·CVSS 7.3
CVE-2026-42498 [HIGH] CVE-2026-42498 tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication.
CVE-2026-42498 tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication.
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.
2026-05-12
Published