Vulnerability Description
Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Apache | Tomcat | >= 7.0.0, <= 7.0.109 |
Related Weaknesses (CWE)
References
- https://lists.apache.org/thread/746nxfxod0wsocxtmv8pb8nkgmwpc6bbMailing ListVendor Advisory
- http://www.openwall.com/lists/oss-security/2026/05/12/11Mailing ListThird Party Advisory
FAQ
What is CVE-2026-43515?
CVE-2026-43515 is a vulnerability with a CVSS score of 9.1 (CRITICAL). Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, ...
How severe is CVE-2026-43515?
CVE-2026-43515 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-43515?
Check the references section above for vendor advisories and patch information. Affected products include: Apache Tomcat.