PT-2026-97309 · Apache · Tomcat Native
CVE-2026-86243
·
Published
2026-09-23
·
Updated
2026-09-30
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Apache Tomcat Native versions 1.3.0 through 1.3.8
Apache Tomcat Native versions 2.0.0 through 2.0.15
Description
A buffer over-read occurs during the TLS handshake, which allows a malicious user to cause a Denial of Service (DoS) by triggering a JVM crash. A buffer over-read is a condition where a program reads data past the end of the intended buffer, potentially accessing unauthorized memory.
Recommendations
Upgrade to version 1.3.9 for versions 1.3.0 through 1.3.8.
Upgrade to version 2.0.16 for versions 2.0.0 through 2.0.15.
Fix
DoS
Buffer Over-read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tomcat Native