Apache · Apache Tomcat · CVE-2026-73180
**Name of the Vulnerable Software and Affected Versions**
Apache Tomcat versions 11.0.0-M1 through 11.0.24
Apache Tomcat versions 10.1.0-M1 through 10.1.57
Apache Tomcat versions 9.0.0.M1 through 9.0.120
Apache Tomcat versions 8.5.0 through 8.5.100
Apache Tomcat versions 7.0.43 through 7.0.109
**Description**
Insufficient session expiration occurs when the session ID for an authenticated HTTP session is changed after a WebSocket connection has been established. In such cases, the WebSocket session remains open instead of closing as required by the Jakarta WebSocket specification when the HTTP session ends.
**Recommendations**
Upgrade to version 11.0.25
Upgrade to version 10.1.58
Upgrade to version 9.0.121