独立行政法人情報処理推進機構(IPA)および一般社団法人JPCERT コーディネーションセンター(JPCERT/CC)は9月24日、Apache Tomcatにおける複数の脆弱性について「Japan Vulnerability Notes(JVN)」で発表した。The Apache Software Foundationでは、Apache Tomcatの15件の脆弱性に対してアドバイザリを公開している。
JVNでは、影響を受けるシステム、想定される影響、対策方法についてはApache Tomcatのアドバイザリを参照するよう案内している。
[SECURITY] CVE-2026-73581 Apache Tomcat - OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore
https://lists.apache.org/thread/r0dj3h1pbn4wv96fhsfrnz3t6874t6do
[SECURITY] CVE-2026-75973 Apache Tomcat - Cross-context authentication mix-up with Jakarta Authentication configured
https://lists.apache.org/thread/njjcdkkzqyzx4n3ffc4ffjmyh5mpl1gr
[SECURITY] CVE-2026-76183 Apache Tomcat - Bypass of security constraints for WebSocket endpoints
https://lists.apache.org/thread/45mxk8nj2q8pkhct6lfxkvtm2jpywrsp
[SECURITY] CVE-2026-77756 Apache Tomcat - Transfer-Encoding honored for HTTP/1.0 requests
https://lists.apache.org/thread/bl5b6rxqh3vb2k9bj2794vhor7o6xl3z
[SECURITY] CVE-2026-77762 Apache Tomcat - Stale HPACK emitter injects trailers into recycled pooled Request
https://lists.apache.org/thread/y5r9fvjo7ol24mkoyoc0st8bqrfyqcyn
[SECURITY] CVE-2026-77791 Apache Tomcat - DoS via busy wait during WebSocket close
https://lists.apache.org/thread/mb1pjjooqytrl6hbvbt3rw1lqwlon4cz
[SECURITY] CVE-2026-78383 Apache Tomcat - AJP DoS via missing request body
https://lists.apache.org/thread/tyqcqk99g7ghgk22641vf67vghcyswnw
[SECURITY] CVE-2026-78437 Apache Tomcat - HTTP/2 DoS via malformed request
https://lists.apache.org/thread/qkmsos3s8chn5053qr466rzwv6sk5gjg
[SECURITY] CVE-2026-79677 Apache Tomcat - WebSocket DoS due to lost asynchronous write timeout
https://lists.apache.org/thread/bzwps6ck4szf2hmksbbon3syyl9qnkv8
[SECURITY] CVE-2026-86243 Apache Tomcat Native - DoS via TLS handshake
https://lists.apache.org/thread/8p4jf02w54m22x0cwpq2x53w3ov8o557
[SECURITY] CVE-2026-86246 Apache Tomcat Native - Insecure OpenSSL options enabled
https://lists.apache.org/thread/dgyvfwb24nbk45ptvlhdyhdhl5o7k5ol
[SECURITY] CVE-2026-86247 Apache Tomcat Native - Client certificate requirements can be down-graded
https://lists.apache.org/thread/obsson6zhvfg0wsp2bx602l61ltj87r1
[SECURITY] CVE-2026-86248 Apache Tomcat - Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
https://lists.apache.org/thread/nmkmjp9l53y8h3oc4n8fc0bkw9dv15sk
[SECURITY] CVE-2026-86350 Apache Tomcat - Regression in fix for CVE-2026-41293 can trigger request header mix-up
https://lists.apache.org/thread/mss45z99lcdd5dtpgcn45dy82f3toswc
[SECURITY] CVE-2026-87022 Apache Tomcat - WebSocket message smuggling with per-message-deflate
https://lists.apache.org/thread/ypvlkjqsq0480fnk9jm6h9qllddwlw4w
