BIT-tomcat-2026-43512
Dashboard / Vulnerabilities / BIT-tomcat-2026-43512
BIT-tomcat-2026-43512
Summary: Apache Tomcat: Digest authenticator will authenticate any unknown user
Details: DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0 through 11.0.21, from 10.1.0 through 10.1.54, from 9.0.0 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0. Older unsupported versions any also be affect Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
References: http://www.openwall.com/lists/oss-security/2026/05/12/8, https://lists.apache.org/thread/7x09x7o12solvclslw3sz0288xc8wx73, https://nvd.nist.gov/vuln/detail/CVE-2026-43512
Affected packages
Package
Name: tomcat
Purl: pkg:bitnami/tomcat
Affected ranges
Type: SEMVER
Events:
