Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.

Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.
Published: 2026-06-29
Score: 6.1 Medium
EPSS: 2.6% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is an improper neutralization of script‑related HTML tags that allows a basic client‑side XSS flaw (CWE‑79, CWE‑80) in the number‑guess example page. An runs in the victim’s browser, potentially exposing sensitive data or executing unintended actions if the user interacts with the page.

Affected Systems

Apache Tomcat releases 7.0.0 through 7.0.109, 8.5.0 through 8.5.100, 9.0.0.M1 through 9.0.118, 10.1.0-M1 through 10.1.55, and 11.0.0-M1 through 11.0.22, including other end‑of‑support versions.

Risk and Exploitability

The flaw can be triggered by accessing the number‑guess example page and requires only a victim to visit the vulnerable URL. The CVSS score of 6.1 indicates a medium severity. The EPSS score of 3% reflects a very low exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Because the attack vector is client‑side, exploitation is limited to users who access the example page; no elevated privileges or attacker‑controlled server side code are required.

Generated by OpenCVE AI on July 17, 2026 at 15:18 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Tomcat to a patched version: 11.0.23 or later, 10.1.56 or later, 9.0.119 or later.
  • In the interim, disable or remove the number‑guess example from the deployed web application to eliminate the vulnerable entry point.
  • Add output‑encoding or Content‑Security‑Policy headers to the affected pages to reduce the impact of any remaining XSS vectors.

Generated by OpenCVE AI on July 17, 2026 at 15:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Ubuntu USN Ubuntu USN USN-8551-1 Tomcat vulnerabilities
History

Tue, 30 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}


Tue, 30 Jun 2026 02:15:00 +0000

Type Values Removed Values Added
First Time appeared Apache
Apache tomcat
Vendors & Products Apache
Apache tomcat

Tue, 30 Jun 2026 00:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N'}

threat_severity

Moderate


Mon, 29 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
Description Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.
Title Apache Tomcat: XSS in number guess example
Weaknesses CWE-80
References

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-06-30T12:50:01.539Z

Reserved: 2026-06-04T09:39:23.609Z

Link: CVE-2026-50229

cve-icon Vulnrichment

Updated: 2026-06-30T12:49:53.409Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-06-29T20:36:24Z

Links: CVE-2026-50229 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-17T15:30:04Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-80

    Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)