PT-2026-97309 · Apache · Tomcat Native

CVE-2026-86243

·

Published

2026-09-23

·

Updated

2026-09-30

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Apache Tomcat Native versions 1.3.0 through 1.3.8 Apache Tomcat Native versions 2.0.0 through 2.0.15
Description A buffer over-read occurs during the TLS handshake, which allows a malicious user to cause a Denial of Service (DoS) by triggering a JVM crash. A buffer over-read is a condition where a program reads data past the end of the intended buffer, potentially accessing unauthorized memory.
Recommendations Upgrade to version 1.3.9 for versions 1.3.0 through 1.3.8. Upgrade to version 2.0.16 for versions 2.0.0 through 2.0.15.

Fix

DoS

Buffer Over-read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86243
OPENSUSE-SU-2026:11898-1
OPENSUSE-SU-2026:11899-1
OPENSUSE-SU-2026:21984-1

Affected Products

Tomcat Native