CVE-2026-78437

Summary

Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail.

This issue affects Apache Tomcat: from 11.0.19 through 11.0.25, from 10.1.53 through 10.1.59, from 9.0.116 through 9.0.121.

Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.

Affected Software

VendorProductVersion RangeStatus
Apache Software FoundationApache Tomcat11.0.19 <= 11.0.25affected
Apache Software FoundationApache Tomcat10.1.53 <= 10.1.59affected
Apache Software FoundationApache Tomcat9.0.116 <= 9.0.121affected
Apache Software FoundationApache Tomcat0 <= 8.5.100unaffected

Weaknesses

  • CWE-459: CWE-459 Incomplete cleanup

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

CVE Program Container

Additional References

References