CVE-2026-65905
published 2026-08-25CVE-2026-65905: Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a…
PriorityP269critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.77%
53.1th percentile
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST
authenticated request with a nonceCount on the upper boundary of the
replay window then that request is replayable once only while the
associated nonceCount remains within the replay window.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.0 < 10.1.58 | 10.1.58 |
| apache | tomcat | >= 11.0.0 < 11.0.25 | 11.0.25 |
| apache | tomcat | 7.0.30 – 7.0.109 | — |
| apache | tomcat | >= 8.5.0 < 9.0.121 | 9.0.121 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.57 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.24 | — |
| apache_software_foundation | apache_tomcat | 7.0.30 – 7.0.109 | — |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.0.M1 – 9.0.120 | — |
| debian | tomcat10 | — | — |
| debian | tomcat11 | — | — |
| debian | tomcat9 | — | — |
| pki-deps_10.6 | pki-servlet-engine | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator.
ghsa_unreviewed·2026-08-26
CVE-2026-65905 CWE-294 Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator.
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST
authenticated request with a nonceCount on the upper boundary of the
replay window then that request is replayable once only while the
associated nonceCount remains within the replay window.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
VulDB
Apache Tomcat up to 11.0.24 DIGEST Authenticator authentication replay (Nessus ID 340139)
vuldb·2026-08-26·CVSS 9.8
CVE-2026-65905 [CRITICAL] Apache Tomcat up to 11.0.24 DIGEST Authenticator authentication replay (Nessus ID 340139)
A vulnerability identified as critical has been detected in Apache Tomcat up to 7.0.109/8.5.100/9.0.120/10.1.57/11.0.24. The impacted element is an unknown function of the component DIGEST Authenticator. The manipulation leads to authentication bypass by capture-replay.
This vulnerability is traded as CVE-2026-65905. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
Red Hat
tomcat: Apache Tomcat: Authentication bypass via limited replay attack in DIGEST authenticator
vendor_redhat·2026-08-25·CVSS 9.8
CVE-2026-65905 [CRITICAL] CWE-294 tomcat: Apache Tomcat: Authentication bypass via limited replay attack in DIGEST authenticator
tomcat: Apache Tomcat: Authentication bypass via limited replay attack in DIGEST authenticator
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST
authenticated request with a nonceCount on the upper boundary of the
replay window then that request is replayable once only while the
associated nonceCount remains within the replay window.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected.
Users are recomme
No detection rules found.
No public exploits indexed.
2026-08-25
Published