VDB
GHSA-x4m4-345f-5h5g
GHSA-x4m4-345f-5h5g
PUBLISHED
CVSS 7.5 HIGH
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Maven | org.apache.tomcat:tomcat | 9.0.13, 10.1.0-M1, 11.0.0-M1 |
| Maven | org.apache.tomcat:tomcat-catalina | 10.1.0-M1, 9.0.13, 11.0.0-M1 |
| Maven | org.apache.tomcat.embed:tomcat-embed-core | 9.0.13, 11.0.0-M1, 11.0.0-M1 |
| Maven | org.apache.tomcat:tomcat-tribes | 9.0.13, 10.1.0-M1, 11.0.0-M1 |
Timeline
- Apr 9, 2026 CVE Published
- Apr 11, 2026 Security Advisory
- Jun 18, 2026 CVE Updated
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-34487 advisory
- https://lists.apache.org/thread/4xpkwolpkrj8v5xzp5nyovtlqp3y850h url
- https://github.com/apache/tomcat package
- https://github.com/apache/tomcat/commit/301bc6efbf72feb14dacfdfa3f50372182736150 url
- https://github.com/apache/tomcat/commit/5eff2a773b8b728083e5195b3183df1b9e12a03d url
- https://github.com/apache/tomcat/commit/f593292a082e5ef9336a8db2b4b522f7f3e36976 url
- https://tomcat.apache.org/security-10.html url
- https://tomcat.apache.org/security-11.html url
- https://tomcat.apache.org/security-9.html url
- http://www.openwall.com/lists/oss-security/2026/04/09/28 url