Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Other versions that have reached end of support may also be affected.
Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119 which fixes the issue.
CVSS Details
- CVSS 3.1 Base Score: 9.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon Linux Ami 2 | — | Upgrade tomcat-admin-webappsUpgrade tomcat-libUpgrade tomcat-webappsUpgrade tomcat-jsp-2.3-apiUpgrade tomcat-el-3.0-apiUpgrade tomcatUpgrade tomcat-docs-webappUpgrade tomcat-servlet-4.0-apiUpgrade tomcat-jsvc | Jul 21, 2026 | Jul 21, 2026 |
| Apache Tomcat | — | Upgrade Apache Tomcat to 11.0.23Upgrade Apache Tomcat to 10.1.56Upgrade Apache Tomcat to 9.0.119Upgrade Apache Tomcat to the latest available version | Jun 30, 2026 | Jun 29, 2026 |
| Atlassian Jira | — | Upgrade to the latest version of Atlassian JIRA | Sep 16, 2026 | Sep 15, 2026 |
| Debian | — | Upgrade tomcat9 | Jul 1, 2026 | Jul 1, 2026 |
| Redhat_linux | — | Upgrade jws7-tomcat-webappsUpgrade tomcat9-jsp-2.3-apiUpgrade jws7-tomcat-el-5.0-apiUpgrade jws7-tomcat-jsp-3.1-apiUpgrade tomcat-docs-webappUpgrade tomcat9-docs-webappUpgrade jws7-tomcat-libUpgrade tomcat-servlet-4.0-apiUpgrade jws7-tomcat-selinuxUpgrade tomcat9-el-3.0-apiUpgrade tomcatUpgrade jws7-tomcat-docs-webappUpgrade jws7-tomcat-javadocUpgrade jws7-tomcat-admin-webappsUpgrade jws7-tomcatUpgrade tomcat-admin-webappsUpgrade tomcat9-webappsUpgrade tomcat9Upgrade tomcat-webappsUpgrade tomcat-el-3.0-apiUpgrade tomcat9-servlet-4.0-apiUpgrade tomcat-libUpgrade jws7-tomcat-servlet-6.0-apiUpgrade tomcat9-admin-webappsUpgrade tomcat9-libNo solution existsUpgrade tomcat-jsp-2.3-api | Jul 17, 2026 | Jun 29, 2026 |
| Ubuntu | — | Upgrade libtomcat8-java (Ubuntu Pro)Upgrade tomcat8-examples (Ubuntu Pro)Upgrade libtomcat8-embed-java (Ubuntu Pro) | Jul 20, 2026 | Jul 15, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub