Apache Software FoundationCVE-2026-86243
Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake...
High7.5CVE-2026-86243 · Published Sep 23, 2026 · updated Oct 6, 2026
Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected. Users are recommended to upgrade to version 1.3.9 or 2.0.16, which fix the issue.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Apache Tomcat Native Product | >= 2.0.0, <= 2.0.15 | No fix yet |
| >= 1.3.0, <= 1.3.8 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity from
- CISA (its enrichment of the CVE record)
- Weakness
- CWE-126
More Apache Software Foundation advisories
All Apache Software Foundation| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 23 | Apache Tomcat Native: insecure default | Critical9.1 | No fix yet |
| Sep 23 | Apache Tomcat Native: race condition | High7.4 | No fix yet |
| Sep 23 | Improper Check for Certificate Revocation vulnerability in Apache Tomcat | Medium6.5 | No fix yet |
| Sep 23 | Apache Tomcat: authentication bypass | Critical9.8 | No fix yet |
| Sep 23 | Apache Tomcat: race condition | High8.1 | No fix yet |
| Sep 23 | Apache Sling XSS: cross-site scripting | Medium6.1 | 2.4.12 |