Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-42498

Опубликовано: 12 мая 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.

A flaw was found in Apache Tomcat. During WebSocket authentication, the HTTP Authentication Header can be exposed to unexpected hosts. This vulnerability leads to information disclosure, potentially allowing an attacker to gain access to sensitive authentication credentials.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Certificate System 10redhat-pki:10/jssFix deferred
Red Hat Enterprise Linux 10jssOut of support scope
Red Hat Enterprise Linux 10mod_proxy_clusterFix deferred
Red Hat Enterprise Linux 10tomcatAffected
Red Hat Enterprise Linux 10tomcat9Affected
Red Hat Enterprise Linux 6tomcat6Affected
Red Hat Enterprise Linux 7tomcatWill not fix
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineAffected
Red Hat Enterprise Linux 8tomcatAffected
Red Hat Enterprise Linux 9jssFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-201
https://bugzilla.redhat.com/show_bug.cgi?id=2476516tomcat-coyote: Apache Tomcat: Information disclosure due to HTTP Authentication Header exposure during WebSocket authentication.

EPSS

Процентиль: 47%
0.006
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.3
ubuntu
4 месяца назад

Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.

CVSS3: 7.3
nvd
4 месяца назад

Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.

CVSS3: 7.3
debian
4 месяца назад

Exposure of HTTP Authentication Header to unexpected hosts during WebS ...

CVSS3: 7.3
redos
3 месяца назад

Уязвимость tomcat11

CVSS3: 7.3
redos
3 месяца назад

Уязвимость tomcat10

EPSS

Процентиль: 47%
0.006
Низкий

6.5 Medium

CVSS3