Новости компьютерной безопасности:

  Latest News

Apache Tomcat Vulnerabilities Let Attackers Bypass Security Controls and Crash Servers

С сайта: Vulnerability(cybersecuritynews.com)

Apache Tomcat Vulnerabilities Let Attackers Bypass Security Controls and Crash Servers

Author: Guru Baran

The Apache Software Foundation has patched a dozen security vulnerabilities in Apache Tomcat, the widely deployed open-source Java servlet container, with fixes rolled into version 11.0.25.

The flaws, disclosed on August 25, 2026, range from low-severity authentication quirks to important-rated bugs that could let attackers sidestep access controls or knock production servers offline through denial-of-service conditions. Organizations running Tomcat 11.0.0-M1 through 11.0.24 in enterprise, cloud, or Linux environments should treat this as a priority patching cycle.

Apache Tomcat Vulnerabilities
Several of the newly fixed issues strike at the heart of Tomcat’s authorization logic. CVE-2026-65182, rated important, is arguably the most concerning of the batch.

It stems from how Tomcat processes security constraints: if a rule covering a longer URL path was defined before a stricter rule for a shorter sub-path, the more restrictive constraint could be silently bypassed, potentially exposing protected resources to unauthorized users.

A related flaw, CVE-2026-68569, also marked important, affected authentication methods such as CLIENT-CERT and SPNEGO. Under certain conditions, users who did not even exist in the DataSourceRealm could still be authenticated, a classic fail-open scenario that undermines the entire purpose of identity verification.

Meanwhile, CVE-2026-65927 revealed an off-by-one error in the RewriteValve component, where the [N] flag caused rule processing to restart at the second rule instead of the first, creating a path for access control bypass via crafted rewrite rules.

Two additional lower-severity bugs round out the access-control cluster. CVE-2026-68525 showed that FORM-based authentication redirects could bypass method-specific constraints, letting attackers reach resources meant to be restricted to POST requests via GET instead.

CVE-2026-66422 involved servlet role-reference definitions being misapplied as realm-level role aliases, deviating from their intended use with Request.isUserInRole().

Beyond authentication issues, Tomcat’s HTTP/2 and WebSocket implementations harbored bugs that could crash servers outright. CVE-2026-68763, rated important, involved an allocation leak in HTTP/2 backlog tracking triggered when a stream was reset, a technique attackers could exploit to exhaust server resources and cause denial of service.

Similarly, CVE-2026-66299 affected the bundled WebSocket chat example, where an unbounded message buffer meant a deliberately slow client could force continuous memory growth until the Tomcat process failed. Notably, administrators who followed prior security guidance to remove example applications are unaffected by this particular bug.

A separate moderate-severity flaw, CVE-2026-65637, revealed that an earlier fix for CVE-2026-32990 addressing strict SNI validation in HTTP/2 was incomplete, allowing a no-authority bypass.

Rounding out the disclosures are two low-severity issues: CVE-2026-73180, where authenticated WebSocket sessions could outlive their parent HTTP session after a session ID change, and CVE-2026-65183, a time-of-check-to-time-of-use race condition affecting permissions on Unix Domain Sockets that could let unauthorized local users gain access. A limited replay-attack vector in DIGEST authentication, CVE-2026-65905, was also closed.

CVE IDDescriptionAffected VersionsCVE-2026-65182Security constraint bypass when a rule for a longer path was defined before a stricter rule for a shorter sub-path11.0.0-M1 to 11.0.24CVE-2026-68569Principal lookup could fail open for CLIENT-CERT/SPNEGO auth, authenticating users not present in the DataSourceRealm11.0.0-M1 to 11.0.24CVE-2026-68763DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset11.0.0-M1 to 11.0.24CVE-2026-65927Off-by-one error in RewriteValve [N] flag causing rule processing to restart at the second rule, enabling access control bypass11.0.0-M1 to 11.0.24CVE-2026-65637Incomplete fix for CVE-2026-32990; HTTP/2 no-authority bypass of strict SNI validation11.0.20 to 11.0.24CVE-2026-68525FORM authentication redirect could bypass method-specific security constraints (e.g., POST-only restrictions accessed via GET)11.0.0-M1 to 11.0.24CVE-2026-66422security-role-ref definitions incorrectly used as role aliases in the Realm instead of only with Request.isUserInRole()11.0.0-M1 to 11.0.24CVE-2026-66299Unbounded buffer in WebSocket chat example allowed a slow client to exhaust memory and crash the Tomcat process11.0.0-M20 to 11.0.24CVE-2026-65905Limited replay attack possible with DIGEST authentication under specific nonceCount conditions11.0.0-M1 to 11.0.24CVE-2026-65183TOCTOU race condition when setting permissions on Unix Domain Sockets, allowing unauthorized local access11.0.0-M1 to 11.0.24CVE-2026-73180Authenticated WebSocket session survives end of HTTP session after a session ID change, violating Jakarta WebSocket spec11.0.0-M1 to 11.0.24
Apache has published fixing commits for each vulnerability, and the recommended remediation is straightforward: upgrade to Apache Tomcat 11.0.25 immediately. Given the mix of access-control bypasses and service-disruption bugs, delaying patches leaves both data exposure and uptime at risk, particularly for internet-facing deployments.

Prevent incidents due to slow investigations. Power your Tier 1 with threat intelligence from 15K SOCs: Integrate TI Lookup in your SOC



#Cyber_Security_News #Vulnerability #Vulnerability_News #cyber_security #cyber_security_news #vulnerability

Оригинальная версия на сайте: Apache Tomcat Vulnerabilities Let Attackers Bypass Security Controls and Crash Servers
Вернуться к списку новостей К свежим новостям Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.

Вернуться к списку новостей Здесь был google AdSense.
Вместо рекламы товаров началась политическая агитация.
Отключено до получения извинений.


Новости проекта CSN:

✉ CSN.net4me.net

Обновление сайта csn.net4me.net

Обновление сайта csn.net4me.net 💻
cyber security news
  • Физически мы переехали на новый сервер. Благодарим наших подписчиков и постоянных читателей за терпение и понимание.
  • Сайт csn.net4me.net полностью адаптирован для работы по шифрованному SSL соединению.
  • Изменен механизм обработки и отображения опасных и критических уязвимостей.

Благодарим что вы с нами.


#CSN_обновление_сайта
https://csn.net4me.net/cyber_security_8301.html

Дополнительный материал

О проекте CSN

Проект CSN.net4me.net родился 16 Марта 2018 года.
Проект находится в самом начале своего развития. Конечно оформление, наполнение будет меняться. Одно останется неизменным - самые свежие новости компьютерной и сетевой безопасности.

О проекте net4me

Проект net4me.net развивался как сборник готовых решений и документации по темам компьютерной безопасности, сетевых решений и СПО (в часности linux). Темпы развития IT отрасли оказались столь быстрыми, что некоторые знания, технологии и информация о них устаревали мгновенно. Тем не менее, некоторый материал net4me.net до сих пор востребован.

Об источниках

Новости берутся CSN из открытых и доступных каждому источников. Авторы проекта стараются подбирать авторитетные и проверенные источники. Но, тем не менее, не несут ответственности за содержимое новостей. В каждой новости указывается источник этой новости, её автор и ссылка на оригинал новости.

Информация

Если вы желаете чтобы новости вашего ресурса были размещены на сайте CSN, то свяжитесь с авторами проекта csn@net4me.net и предложите ссылку на rss или xml ленту новостей вашего ресурса. Любая предложенная информация будет рассмотрена редакцией.