Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120.
Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.
CVSS Details
- CVSS 3.1 Base Score: 8.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Apache Tomcat | — | Upgrade Apache Tomcat to 10.1.59Upgrade Apache Tomcat to 11.0.25Upgrade Apache Tomcat to the latest available versionUpgrade Apache Tomcat to 9.0.121 | Aug 26, 2026 | Aug 25, 2026 |
| Debian | — | Upgrade tomcat9 | Aug 27, 2026 | Aug 27, 2026 |
| Redhat_linux | — | Upgrade jws6-tomcat-javadocNo solution existsUpgrade jws6-tomcat-docs-webappUpgrade jws6-tomcat-libUpgrade jws6-tomcat-servlet-6.0-apiUpgrade jws6-tomcat-admin-webappsUpgrade jws6-tomcat-jsp-3.1-apiUpgrade jws6-tomcat-selinuxUpgrade jws6-tomcatUpgrade jws6-tomcat-webappsUpgrade jws6-tomcat-el-5.0-api | Sep 30, 2026 | Aug 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub