独立行政法人情報処理推進機構(IPA)は9月25日、Apache Tomcatにおける複数の脆弱性について「JVN iPedia」で発表した。影響を受けるシステムは以下の通り。
Apache Software Foundation
Apache Tomcat
The Apache Software Foundationでは9月23日、Apache Tomcatの15件の脆弱性に対してアドバイザリを公開している。
JVN iPediaでは、想定される影響、対策方法についてはApache Tomcatのアドバイザリを参照するよう案内している。
The Apache Software Foundation : [SECURITY] CVE-2026-73581 Apache Tomcat - OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore
https://lists.apache.org/thread/r0dj3h1pbn4wv96fhsfrnz3t6874t6do
The Apache Software Foundation : [SECURITY] CVE-2026-75973 Apache Tomcat - Cross-context authentication mix-up with Jakarta Authentication configured
https://lists.apache.org/thread/njjcdkkzqyzx4n3ffc4ffjmyh5mpl1gr
The Apache Software Foundation : [SECURITY] CVE-2026-76183 Apache Tomcat - Bypass of security constraints for WebSocket endpoints
https://lists.apache.org/thread/45mxk8nj2q8pkhct6lfxkvtm2jpywrsp
The Apache Software Foundation : [SECURITY] CVE-2026-77756 Apache Tomcat - Transfer-Encoding honored for HTTP/1.0 requests
https://lists.apache.org/thread/bl5b6rxqh3vb2k9bj2794vhor7o6xl3z
The Apache Software Foundation : [SECURITY] CVE-2026-77762 Apache Tomcat - Stale HPACK emitter injects trailers into recycled pooled Request
https://lists.apache.org/thread/y5r9fvjo7ol24mkoyoc0st8bqrfyqcyn
The Apache Software Foundation : [SECURITY] CVE-2026-77791 Apache Tomcat - DoS via busy wait during WebSocket close
https://lists.apache.org/thread/mb1pjjooqytrl6hbvbt3rw1lqwlon4cz
The Apache Software Foundation : [SECURITY] CVE-2026-78383 Apache Tomcat - AJP DoS via missing request body
https://lists.apache.org/thread/tyqcqk99g7ghgk22641vf67vghcyswnw
The Apache Software Foundation : [SECURITY] CVE-2026-78437 Apache Tomcat - HTTP/2 DoS via malformed request
https://lists.apache.org/thread/qkmsos3s8chn5053qr466rzwv6sk5gjg
The Apache Software Foundation : [SECURITY] CVE-2026-79677 Apache Tomcat - WebSocket DoS due to lost asynchronous write timeout
https://lists.apache.org/thread/bzwps6ck4szf2hmksbbon3syyl9qnkv8
The Apache Software Foundation : [SECURITY] CVE-2026-86243 Apache Tomcat Native - DoS via TLS handshake
https://lists.apache.org/thread/8p4jf02w54m22x0cwpq2x53w3ov8o557
The Apache Software Foundation : [SECURITY] CVE-2026-86246 Apache Tomcat Native - Insecure OpenSSL options enabled
https://lists.apache.org/thread/dgyvfwb24nbk45ptvlhdyhdhl5o7k5ol
The Apache Software Foundation : [SECURITY] CVE-2026-86247 Apache Tomcat Native - Client certificate requirements can be down-graded
https://lists.apache.org/thread/obsson6zhvfg0wsp2bx602l61ltj87r1
The Apache Software Foundation : [SECURITY] CVE-2026-86248 Apache Tomcat - Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
https://lists.apache.org/thread/nmkmjp9l53y8h3oc4n8fc0bkw9dv15sk
The Apache Software Foundation : [SECURITY] CVE-2026-86350 Apache Tomcat - Regression in fix for CVE-2026-41293 can trigger request header mix-up
https://lists.apache.org/thread/mss45z99lcdd5dtpgcn45dy82f3toswc
The Apache Software Foundation : [SECURITY] CVE-2026-87022 Apache Tomcat - WebSocket message smuggling with per-message-deflate
https://lists.apache.org/thread/ypvlkjqsq0480fnk9jm6h9qllddwlw4w
