Vulnerability Description
DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0. Older unsupported versions any also be affect Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | >= 7.0.0, <= 7.0.109 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/7x09x7o12solvclslw3sz0288xc8wx73Mailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/05/12/8Mailing ListThird Party Advisory
FAQ
What is CVE-2026-43512?
CVE-2026-43512 is a vulnerability with a CVSS score of 9.8 (CRITICAL). DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, fro...
How severe is CVE-2026-43512?
CVE-2026-43512 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-43512?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat.