CVE-2026-42498: Apache Tomcat: WebSocket authentication header exposure
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tomcat10to a version that resolves this vulnerability.Fixed in 10.1.55-1~deb12u1Fixed in 10.1.55-1~deb13u1Fixed in 10.1.55-1 - Upgrade
Upgrade
debian/tomcat11to a version that resolves this vulnerability.Fixed in 11.0.22-1~deb13u1Fixed in 11.0.22-2 - Upgrade
Upgrade
debian/tomcat9to a version that resolves this vulnerability.Fixed in 9.0.118-0+deb11u1Fixed in 9.0.70-2Fixed in 9.0.95-1Fixed in 9.0.118-1 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.22 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.55 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.118
Event History
Frequently Asked Questions
What is the severity of CVE-2026-42498?
The severity of CVE-2026-42498 is considered high due to the risk of exposing sensitive HTTP authentication headers.
How do I fix CVE-2026-42498?
To fix CVE-2026-42498, update Apache Tomcat to a version that is not affected, such as 11.0.22 or higher, 10.1.55 or higher, 9.0.118 or higher, 8.5.101 or higher, or 7.0.110 or higher.
What versions of Apache Tomcat are affected by CVE-2026-42498?
CVE-2026-42498 affects Apache Tomcat versions from 11.0.0-M1 through 11.0.21, 10.1.0-M1 through 10.1.54, 9.0.2 through 9.0.117, 8.5.24 through 8.5.100, and 7.0.83 through 7.0.109.
What does CVE-2026-42498 expose?
CVE-2026-42498 exposes HTTP Authentication headers to unexpected hosts during WebSocket authentication.
Is there a workaround for CVE-2026-42498?
There are no documented workarounds for CVE-2026-42498; the recommended action is to upgrade to a fixed version.