VDB

DEBIAN-CVE-2026-34483

DEBIAN-CVE-2026-34483 PUBLISHED CVSS 7.5 HIGH

Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.

Risk Scores

CVSS v3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Debian:14tomcat100, 10.1.52-1~deb12u1, 10.1.52-1
Debian:14tomcat90, 0
Debian:12tomcat1010.1.34-0, 10.1.10-1, 10.1.13-1
Debian:14tomcat110, *, 11.0.6-1
Debian:11tomcat99.0.43-2, 9.0.43-1, 0
Debian:13tomcat90, 0
Debian:12tomcat90, 0
Debian:13tomcat1010.1.52-1~deb13u1, 10.1.54-1, 10.1.52-2
Debian:13tomcat1111.0.21-1, 11.0.6-1, 11.0.15-1

Timeline

  • Apr 9, 2026 CVE Published
  • Apr 28, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›