CVE-2026-43513
published 2026-05-12CVE-2026-43513: Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from…
PriorityP350high7.5CVSS 3.1
AVNACLPRNUINSUCHINAN
EPSS
0.47%
37.9th percentile
Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Older unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | >= 10.1.0 < 10.1.55 | 10.1.55 |
| apache | tomcat | >= 11.0.0 < 11.0.22 | 11.0.22 |
| apache | tomcat | 7.0.0 – 7.0.109 | — |
| apache | tomcat | 8.5.0 – 8.5.100 | — |
| apache | tomcat | >= 9.0.0 < 9.0.118 | 9.0.118 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.54 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.21 | — |
| apache_software_foundation | apache_tomcat | 7.0.0 – 7.0.109 | — |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.0.M1 – 9.0.117 | — |
| ubuntu | tomcat10 | — | — |
| ubuntu | tomcat6 | — | — |
| ubuntu | tomcat7 | — | — |
| ubuntu | tomcat9 | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
vendor_ubuntu9.8CRITICAL
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Apache Tomcat up to 11.0.21 LockOutRealm case sensitivity (Nessus ID 314335)
vuldb·2026-05-19·CVSS 7.5
CVE-2026-43513 [HIGH] Apache Tomcat up to 11.0.21 LockOutRealm case sensitivity (Nessus ID 314335)
A vulnerability was found in Apache Tomcat up to 7.0.109/8.5.100/9.0.117/10.1.54/11.0.21 and classified as critical. Affected by this vulnerability is an unknown functionality of the component LockOutRealm. The manipulation results in improper handling of case sensitivity.
This vulnerability is identified as CVE-2026-43513. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.
GHSA
Apache Tomcat: LockOutRealm treats user names as case-sensitive
ghsa·2026-05-12
CVE-2026-43513 [HIGH] CWE-178 Apache Tomcat: LockOutRealm treats user names as case-sensitive
Apache Tomcat: LockOutRealm treats user names as case-sensitive
Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Older unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
GHSA
GHSA-5mp6-jrq3-r938: Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat
ghsa_unreviewed·2026-05-12
CVE-2026-43513 CWE-178 GHSA-5mp6-jrq3-r938: Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat
Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Older unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2026-06-10·CVSS 7.5
CVE-2026-41284 [HIGH] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat did not properly limit the size of
WebDAV LOCK and PROPFIND request bodies. A remote attacker could
use this issue to cause Tomcat to consume excessive memory,
resulting in a denial of service. (CVE-2026-41284)
It was discovered that Tomcat incorrectly validated HTTP/2 header
fields. A remote attacker could use this issue to cause Tomcat to
crash or possibly execute arbitrary code. (CVE-2026-41293)
It was discovered that Tomcat did not properly clear HTTP
authentication headers during WebSocket connection upgrades and
redirects. A remote attacker could use this issue to obtain
sensitive credentials. (CVE-2026-42498)
It was discovered that Tomcat incorrectly handled digest
Ubuntu
Tomcat vulnerabilities
vendor_ubuntu·2026-06-04·CVSS 9.8
CVE-2026-43513 [CRITICAL] Tomcat vulnerabilities
Title: Tomcat vulnerabilities
Summary: Several security issues were fixed in Tomcat.
It was discovered that Tomcat incorrectly handled digest
authentication. A remote attacker could possibly use this issue to
bypass authentication restrictions. (CVE-2026-43512)
It was discovered that Tomcat incorrectly handled case sensitivity
in LockOutRealm. A remote attacker could possibly use this issue to
bypass account lockout protections and obtain sensitive information.
(CVE-2026-43513)
It was discovered that Tomcat incorrectly handled authorization when
multiple method constraints defined the same HTTP method. A remote
attacker could possibly use this issue to bypass authorization
restrictions. (CVE-2026-43515)
Instructions: After a standard system update you need to restart Tomcat to make
al
Red Hat
tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm
vendor_redhat·2026-05-12·CVSS 7.5
CVE-2026-43513 [HIGH] CWE-178 tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm
tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm
Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Older unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
In Apache Tomcat, LockOutRealm mishandled case sensitivity in usernames, resulting in less effective blocking of brute force attacks.
Statement: A flaw was found in Apache Tomcat's LockOutRealm. When configured with an underlying Realm where usernames are case-insensitive, the LockOutRealm does no
No detection rules found.
No public exploits indexed.
2026-05-12
Published