CVE-2026-78437
Received Received - Intake

Incomplete Cleanup Flaw in Apache Tomcat

Vulnerability report for CVE-2026-78437, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: Apache Software Foundation

Description

Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail. This issue affects Apache Tomcat: from 11.0.19 through 11.0.25, from 10.1.53 through 10.1.59, from 9.0.116 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
apache tomcat From 11.0.19 (inc) to 11.0.25 (inc)
apache tomcat From 10.1.53 (inc) to 10.1.59 (inc)
apache tomcat From 9.0.116 (inc) to 9.0.121 (inc)
apache tomcat 11.0.26
apache tomcat 10.1.60
apache tomcat 9.0.122

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-459 The product does not properly "clean up" and remove temporary or supporting resources after they have been used.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an incomplete cleanup vulnerability in Apache Tomcat where a malformed request could cause another user's request to fail, depending on timing. It affects specific versions of Tomcat between certain ranges.

Detection Guidance

This vulnerability is specific to Apache Tomcat versions between 11.0.19-11.0.25, 10.1.53-10.1.59, and 9.0.116-9.0.121. Detection involves checking the installed Tomcat version. Use commands like 'catalina.sh version' or 'java -cp catalina.jar org.apache.catalina.util.ServerInfo' to verify the version.

Impact Analysis

The vulnerability may cause denial of service for legitimate users by failing their requests due to a malformed request from another user. This could disrupt normal operations of affected Tomcat servers.

Compliance Impact

This vulnerability may impact compliance with GDPR or HIPAA by potentially causing unauthorized data access or processing disruptions due to malformed requests failing user requests. However, the specific compliance impact depends on the affected system's configuration and data handling.

Mitigation Strategies

Upgrade Apache Tomcat to the fixed versions: 11.0.26, 10.1.60, or 9.0.122. Download the latest version from the official Apache Tomcat website and replace the existing installation.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-78437. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart