Apache · Apache Tomcat · CVE-2026-50229
**Name of the Vulnerable Software and Affected Versions**
Apache Tomcat versions 11.0.0-M1 through 11.0.22
Apache Tomcat versions 10.1.0-M1 through 10.1.55
Apache Tomcat versions 9.0.0.M1 through 9.0.118
Apache Tomcat versions 8.5.0 through 8.5.100
Apache Tomcat versions 7.0.0 through 7.0.109
**Description**
Cross-Site Scripting (XSS) occurs in the number guess example application due to improper neutralization of script-related HTML tags in a web page. XSS is a flaw that allows an attacker to inject malicious scripts into content delivered to other users.
**Recommendations**
Upgrade versions 11.0.0-M1 through 11.0.22 to 11.0.23.
Upgrade versions 10.1.0-M1 through 10.1.55 to 10.1.56.
Upgrade versions 9.0.0.M1 through 9.0.118 to 9.0.119.