CVE-2026-34483: Apache Tomcat: Incomplete escaping of JSON access logs
Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tomcat (JsonAccessLogValve)to a version that resolves this vulnerability.Fixed in 11.0.21 - Upgrade
Upgrade
Apache Tomcat (JsonAccessLogValve)to a version that resolves this vulnerability.Fixed in 10.1.54 - Upgrade
Upgrade
Apache Tomcat (JsonAccessLogValve)to a version that resolves this vulnerability.Fixed in 9.0.117
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34483?
CVE-2026-34483 is classified as a medium severity vulnerability due to the incomplete escaping of JSON in the access logs.
How do I fix CVE-2026-34483?
To mitigate CVE-2026-34483, upgrade Apache Tomcat to a version that is not affected, specifically to versions 11.0.21 or later, 10.1.54 or later, or 9.0.117 or later.
Which versions of Apache Tomcat are affected by CVE-2026-34483?
CVE-2026-34483 affects Apache Tomcat versions from 11.0.0-M1 through 11.0.20, 10.1.0-M1 through 10.1.53, and 9.0.40 through 9.0.116.
What components of Apache Tomcat are vulnerable in CVE-2026-34483?
The vulnerability in CVE-2026-34483 occurs in the JsonAccessLogValve component of Apache Tomcat.
What kind of impact does CVE-2026-34483 have?
CVE-2026-34483 can lead to improper output encoding, which may expose sensitive information in JSON access logs.