Description
Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash.



This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected.



Users are recommended to upgrade to version 1.3.9 or 2.0.16, which fix the issue.
Published: 2026-09-23
Score: n/a
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

A buffer over-read occurs in Apache Tomcat Native during the TLS handshake, allowing a crafted request to cause the Java Virtual Machine to crash. This leads to a full denial of service for the affected Tomcat instance until the process is restarted. The flaw is identified as CWE-126, a type of out‑of-bounds read.

Affected Systems

Apache Tomcat Native versions 2.0.0 through 2.0.15 and 1.3.0 through 1.3.8 are impacted; earlier unsupported releases may also be affected. The official fix is available in 2.0.16 and 1.3.9.

Risk and Exploitability

The vulnerability can be triggered by a malicious actor initiating a TLS handshake that contains an improperly crafted record. Based on the description, it is inferred that such an attack can be performed remotely over the network. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting that publicly known exploitation may be limited. Nevertheless, remote exploitation would result in a JVM crash and immediate service disruption.

Generated by OpenCVE AI on September 23, 2026 at 13:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Apache Tomcat Native to at least version 1.3.9 or 2.0.16.
  • Restrict or disable unnecessary TLS handshakes on exposed network ports to reduce the attack surface.
  • Implement monitoring to detect JVM crashes and automatically restart the Tomcat service to maintain availability.

Generated by OpenCVE AI on September 23, 2026 at 13:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 12:45:00 +0000

Type Values Removed Values Added
Description Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected. Users are recommended to upgrade to version 1.3.9 or 2.0.16, which fix the issue.
Title Apache Tomcat Native: DoS via TLS handshake
Weaknesses CWE-126
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: apache

Published:

Updated: 2026-09-23T15:29:11.463Z

Reserved: 2026-09-06T09:21:33.313Z

Link: CVE-2026-86243

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-23T13:17:30.993

Modified: 2026-09-23T13:17:30.993

Link: CVE-2026-86243

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T14:00:05Z

Weaknesses