Status: UPDATED | Advisory ID: CVE-2026-78437
| CVE | CVE-2026-78437 |
| CVSS Score / Version | 7.3 (High) / CVSS v3.1 |
| Updated | 2026-09-23 |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
| CVSS Prose | attack vector is network; attack complexity is low; privileges required is none; user interaction is none; scope is unchanged; confidentiality impact is low; integrity impact is low; availability impact is low. |
| Affected products | Apache Software Foundation Apache Tomcat |
| Classified as | CWE-459 (Incomplete Cleanup) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| Apache Software Foundation | Apache Tomcat |
| Subsystems | General OT |
| Sectors | Multiple |
Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail.
This issue affects Apache Tomcat: from 11.0.19 through 11.0.25, from 10.1.53 through 10.1.59, from 9.0.116 through 9.0.121.
Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue. (NVD)
Monitor Apache Software Foundation's web page for any future patch releases.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-78437 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-78437 |