Описание
Apache Tomcat - WebSocket authentication header exposure
Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.21 Apache Tomcat 10.1.0-M1 to 10.1.54 Apache Tomcat 9.0.2 to 9.0.117 Older, unsupported versions may also be affected
Description: If a WebSocket request was redirected after authentication, Tomcat's WebSocket client would present the most recent authentication header to the redirect target host.
Mitigation: Users of the affected versions should apply one of the following mitigations:
- Upgrade to Apache Tomcat 11.0.22 or later
- Upgrade to Apache Tomcat 10.1.55 or later
- Upgrade to Apache Tomcat 9.0.118 or later
Credit: This issue was identified by lokerxx
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2026-42498
- https://github.com/apache/tomcat/commit/169d725788ea6aec217ecac70fe4161c837ba423
- https://github.com/apache/tomcat/commit/6cbe274592ef2d11607b5b188e1df649de52f8d5
- https://github.com/apache/tomcat/commit/b7b173694d588ddcfa432f079baf763cbbbaa5c4
- https://lists.apache.org/thread/n61zwf75jrv09rz90j4jssncm244bwdb
- https://tomcat.apache.org/security-10.html
- https://tomcat.apache.org/security-11.html
- https://tomcat.apache.org/security-9.html
- http://www.openwall.com/lists/oss-security/2026/05/12/14
Пакеты
org.apache.tomcat.embed:tomcat-embed-core
< 9.0.118
9.0.118
org.apache.tomcat.embed:tomcat-embed-core
>= 10.1.0-M1, < 10.1.55
10.1.55
org.apache.tomcat.embed:tomcat-embed-core
>= 11.0.0-M1, < 11.0.22
11.0.22
org.apache.tomcat:tomcat
< 9.0.118
9.0.118
org.apache.tomcat:tomcat
>= 10.1.0-M1, < 10.1.55
10.1.55
org.apache.tomcat:tomcat
>= 11.0.0-M1, < 11.0.22
11.0.22
org.apache.tomcat:tomcat-catalina
< 9.0.118
9.0.118
org.apache.tomcat:tomcat-catalina
>= 10.1.0-M1, < 10.1.55
10.1.55
org.apache.tomcat:tomcat-catalina
>= 11.0.0-M1, < 11.0.22
11.0.22
Связанные уязвимости
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.
Exposure of HTTP Authentication Header to unexpected hosts during WebS ...
Уязвимость сервера приложений Apache Tomcat, связанная с отсутствием защиты служебных данных, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации