VDB

DEBIAN-CVE-2026-43513

DEBIAN-CVE-2026-43513 PUBLISHED CVSS 7.5 HIGH

Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Affected Products

VendorProductVersions
Debian:14tomcat1111.0.6-1, 0, 11.0.11-1
Debian:14tomcat100, 10.1.54-1, 10.1.52-2
Debian:11tomcat99.0.43-3, 9.0.53-1, 9.0.54-1
Debian:13tomcat1010.1.54-1, 0, 10.1.40-1
Debian:12tomcat1010.1.33-1, 10.1.20-1, 10.1.23-1
Debian:13tomcat90
Debian:13tomcat1111.0.11-1, 0, 11.0.15-1
Debian:14tomcat90
Debian:12tomcat90

Timeline

  • May 12, 2026 CVE Published
  • May 15, 2026 CVE Updated
Open in Interactive Console →
$ Console Community · 100/wk Open console ›