Description
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109.

Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.
Published: 2026-05-12
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in Apache Tomcat causes the HTTP authentication header to be sent to unexpected hosts during WebSocket handshakes, exposing credentials that should remain confidential. The vulnerability is a classic example of Sensitive Data Exposure (CWE-200) and enables an attacker to obtain the raw authentication header, effectively compromising user identities and allowing further unauthorized access.

Affected Systems

Products impacted are Apache Tomcat versions 11.0.0-M1 through 11.0.21, 10.1.0-M1 through 10.1.54, 9.0.2 through 9.0.117, 8.5.24 through 8.5.100, and 7.0.83 through 7.0.109. The affected vendor is the Apache Software Foundation.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity, and the EPSS score of less than 1% suggests a low but nonzero probability of exploitation. This vulnerability is not listed in the CISA KEV catalog, indicating no widespread public exploitation yet. The likely attack vector is a remote WebSocket handshake initiated by an attacker who can convince a legitimate client or server to perform the vulnerable authentication flow. Because the authentication header is exposed to an unintended host, the attacker could capture credentials and use them to impersonate a legitimate user. Given the high CVSS score and the potential for credential compromise, the risk remains significant.

Generated by OpenCVE AI on May 13, 2026 at 18:08 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Tomcat to 11.0.22, 10.1.55, or 9.0.118, whichever applies to your environment, to apply the vendor‑supplied fix.
  • Deploy a Web Application Firewall or an intrusion detection system that can detect and block insecure WebSocket handshake transmissions.
  • Implement network segmentation or firewall rules to restrict outgoing WebSocket traffic from the client to only legitimate servers, mitigating the risk of unintended host exposure.

Generated by OpenCVE AI on May 13, 2026 at 18:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-fv25-8xcx-gqjc Apache Tomcat - WebSocket authentication header exposure
History

Thu, 14 May 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache tomcat
CPEs cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*
Vendors & Products Apache tomcat

Wed, 13 May 2026 16:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 12 May 2026 18:30:00 +0000

Type Values Removed Values Added
References

Tue, 12 May 2026 18:00:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache apache Tomcat
Vendors & Products Apache
Apache apache Tomcat

Tue, 12 May 2026 16:00:00 +0000

Type Values Removed Values Added
Description Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.
Title Apache Tomcat: WebSocket authentication header exposure
Weaknesses CWE-200
References

Subscriptions

Apache Apache Tomcat Tomcat
cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-05-13T15:59:04.361Z

Reserved: 2026-04-27T22:13:05.647Z

Link: CVE-2026-42498

cve-icon Vulnrichment

Updated: 2026-05-12T17:40:58.470Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-12T16:16:17.800

Modified: 2026-05-14T18:51:59.217

Link: CVE-2026-42498

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-13T18:15:16Z

Weaknesses