PT-2026-53741 · Apache+2 · Apache Tomcat+2

·

CVE-2026-53404

·

Published

2026-06-22

·

Updated

2026-09-11

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Apache Tomcat versions 11.0.0-M1 through 11.0.22 Apache Tomcat versions 10.1.0-M1 through 10.1.55 Apache Tomcat versions 9.0.0.M1 through 9.0.118 Apache Tomcat versions 8.5.0 through 8.5.100
Description An incorrect control flow implementation in the rewrite valve causes subsequent non-OR conditions to be skipped if the first condition in an OR chain matches.
Recommendations Upgrade to version 11.0.23 Upgrade to version 10.1.56 Upgrade to version 9.0.119

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11859
BIT-TOMCAT-2026-53404
CVE-2026-53404
OESA-2026-2947
OESA-2026-2948
OESA-2026-2949
OESA-2026-2950
OPENSUSE-SU-2026:11195-1
OPENSUSE-SU-2026:11208-1
OPENSUSE-SU-2026:11209-1
OPENSUSE-SU-2026:21327-1
OPENSUSE-SU-2026:21328-1
OPENSUSE-SU-2026:21329-1
RHSA-2026:29203
RHSA-2026:43401
RHSA-2026:49951
SUSE-SU-2026:22646-1
SUSE-SU-2026:22647-1
SUSE-SU-2026:22648-1
SUSE-SU-2026:3087-1
SUSE-SU-2026:3088-1
SUSE-SU-2026:3112-1
SUSE-SU-2026:3167-1
USN-8551-1

Affected Products

Apache Tomcat
Red Os
Ubuntu