HIGH
Apache Tomcat Native: DoS via TLS handshake
Published Sep 23, 2026
7.5
HIGHCVSS 3.1
EPSS 0.40%
Description
Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash.
This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected.
Users are recommended to upgrade to version 1.3.9 or 2.0.16, which fix the issue.
Affected products
-
- Version 1.3.0StatusaffectedConstraints<=1.3.8
- Version 2.0.0StatusaffectedConstraints<=2.0.15
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Apache Software Foundation | Apache Tomcat Native | unaffected |
|
OR
- ≥ 1.3.0 · < 1.3.9
- ≥ 2.0.0 · < 2.0.16
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- http://www.openwall.com/lists/oss-security/2026/09/23/31
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85267 Advisory
- https://lists.apache.org/thread/8p4jf02w54m22x0cwpq2x53w3ov8o557 vendor-advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2026/09/23/31 | ||
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-85267 | Advisory | |
| https://lists.apache.org/thread/8p4jf02w54m22x0cwpq2x53w3ov8o557 | vendor-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Sep 23, 2026
Updated Sep 23, 2026
Reserved Sep 6, 2026
Link CVE-2026-86243
CISA Vulnrichment
Updated Sep 23, 2026
ENISA EUVD
EUVD-2026-85267 Assigner apache
Published Sep 23, 2026
Updated Sep 23, 2026
Exploited since n/a
Link EUVD-2026-85267