CVE-2026-43513: Apache Tomcat: LockOutRealm treats user names as case-sensitive
Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tomcat10to a version that resolves this vulnerability.Fixed in 10.1.55-1~deb12u1Fixed in 10.1.55-1~deb13u1Fixed in 10.1.55-1 - Upgrade
Upgrade
debian/tomcat11to a version that resolves this vulnerability.Fixed in 11.0.22-1~deb13u1Fixed in 11.0.22-2 - Upgrade
Upgrade
debian/tomcat9to a version that resolves this vulnerability.Fixed in 9.0.118-0+deb11u1Fixed in 9.0.70-2Fixed in 9.0.95-1Fixed in 9.0.118-1 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.22 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.55 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.118
Event History
Frequently Asked Questions
What is the severity of CVE-2026-43513?
CVE-2026-43513 has been categorized as a medium-severity vulnerability due to its potential impact on user authentication.
How do I fix CVE-2026-43513?
To fix CVE-2026-43513, upgrade to the latest version of Apache Tomcat that has addressed this case sensitivity issue in the LockOutRealm.
Which versions of Apache Tomcat are affected by CVE-2026-43513?
CVE-2026-43513 affects Apache Tomcat versions 7.0.0 to 7.0.109, 8.5.0 to 8.5.100, 9.0.0.M1 to 9.0.117, 10.1.0-M1 to 10.1.54, and 11.0.0-M1 to 11.0.21.
What components are involved in CVE-2026-43513?
CVE-2026-43513 specifically involves the LockOutRealm component in Apache Tomcat which improperly handles case sensitivity in usernames.
Is there a workaround for CVE-2026-43513?
Currently, there are no official workarounds provided for CVE-2026-43513, so upgrading to a patched version is recommended.