OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-78437

HIGH · CVSS 7.3 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Apache Tomcat versions 11.0.19 to 11.0.25, 10.1.53 to 10.1.59, and 9.0.116 to 9.0.121 are vulnerable to an incomplete cleanup issue that may allow a malformed request to interfere with requests from other users, potentially leading to denial of service. Organizations using affected versions should prioritize upgrading to versions 11.0.26, 10.1.60, or 9.0.122 to mitigate this high-severity vulnerability.

CVE
CVE-2026-78437
Severity
HIGH
CVSS
7.3
EPSS
0.26%
Apache

Original NVD Description

Incomplete cleanup vulnerability in Apache Tomcat allows a malformed request to potentially (depends on timing) cause one request from another user to fail. This issue affects Apache Tomcat: from 11.0.19 through 11.0.25, from 10.1.53 through 10.1.59, from 9.0.116 through 9.0.121. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.0.122, which fix the issue.