Apache Tomcat に複数の脆弱性 | ScanNetSecurity
2026.09.28(月)

Apache Tomcat に複数の脆弱性

独立行政法人情報処理推進機構(IPA)および一般社団法人JPCERT コーディネーションセンター(JPCERT/CC)は9月24日、Apache Tomcatにおける複数の脆弱性について「Japan Vulnerability Notes(JVN)」で発表した。

脆弱性と脅威

 独立行政法人情報処理推進機構(IPA)および一般社団法人JPCERT コーディネーションセンター(JPCERT/CC)は9月24日、Apache Tomcatにおける複数の脆弱性について「Japan Vulnerability Notes(JVN)」で発表した。The Apache Software Foundationでは、Apache Tomcatの15件の脆弱性に対してアドバイザリを公開している。

 JVNでは、影響を受けるシステム、想定される影響、対策方法についてはApache Tomcatのアドバイザリを参照するよう案内している。

[SECURITY] CVE-2026-73581 Apache Tomcat - OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore
https://lists.apache.org/thread/r0dj3h1pbn4wv96fhsfrnz3t6874t6do

[SECURITY] CVE-2026-75973 Apache Tomcat - Cross-context authentication mix-up with Jakarta Authentication configured
https://lists.apache.org/thread/njjcdkkzqyzx4n3ffc4ffjmyh5mpl1gr

[SECURITY] CVE-2026-76183 Apache Tomcat - Bypass of security constraints for WebSocket endpoints
https://lists.apache.org/thread/45mxk8nj2q8pkhct6lfxkvtm2jpywrsp

[SECURITY] CVE-2026-77756 Apache Tomcat - Transfer-Encoding honored for HTTP/1.0 requests
https://lists.apache.org/thread/bl5b6rxqh3vb2k9bj2794vhor7o6xl3z

[SECURITY] CVE-2026-77762 Apache Tomcat - Stale HPACK emitter injects trailers into recycled pooled Request
https://lists.apache.org/thread/y5r9fvjo7ol24mkoyoc0st8bqrfyqcyn

[SECURITY] CVE-2026-77791 Apache Tomcat - DoS via busy wait during WebSocket close
https://lists.apache.org/thread/mb1pjjooqytrl6hbvbt3rw1lqwlon4cz

[SECURITY] CVE-2026-78383 Apache Tomcat - AJP DoS via missing request body
https://lists.apache.org/thread/tyqcqk99g7ghgk22641vf67vghcyswnw

[SECURITY] CVE-2026-78437 Apache Tomcat - HTTP/2 DoS via malformed request
https://lists.apache.org/thread/qkmsos3s8chn5053qr466rzwv6sk5gjg

[SECURITY] CVE-2026-79677 Apache Tomcat - WebSocket DoS due to lost asynchronous write timeout
https://lists.apache.org/thread/bzwps6ck4szf2hmksbbon3syyl9qnkv8

[SECURITY] CVE-2026-86243 Apache Tomcat Native - DoS via TLS handshake
https://lists.apache.org/thread/8p4jf02w54m22x0cwpq2x53w3ov8o557

[SECURITY] CVE-2026-86246 Apache Tomcat Native - Insecure OpenSSL options enabled
https://lists.apache.org/thread/dgyvfwb24nbk45ptvlhdyhdhl5o7k5ol

[SECURITY] CVE-2026-86247 Apache Tomcat Native - Client certificate requirements can be down-graded
https://lists.apache.org/thread/obsson6zhvfg0wsp2bx602l61ltj87r1

[SECURITY] CVE-2026-86248 Apache Tomcat - Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
https://lists.apache.org/thread/nmkmjp9l53y8h3oc4n8fc0bkw9dv15sk

[SECURITY] CVE-2026-86350 Apache Tomcat - Regression in fix for CVE-2026-41293 can trigger request header mix-up
https://lists.apache.org/thread/mss45z99lcdd5dtpgcn45dy82f3toswc

[SECURITY] CVE-2026-87022 Apache Tomcat - WebSocket message smuggling with per-message-deflate
https://lists.apache.org/thread/ypvlkjqsq0480fnk9jm6h9qllddwlw4w

《ScanNetSecurity》

関連記事

「経理」「営業」「企画」「プログラミング」「デザイン」と並ぶ、事業で成功するためのビジネスセンスが「セキュリティ」
「経理」「営業」「企画」「プログラミング」「デザイン」と並ぶ、事業で成功するためのビジネスセンスが「セキュリティ」

ページ右上「ユーザー登録」から会員登録すれば会員限定記事を閲覧できます。毎週月曜の朝、先週一週間のセキュリティ動向を総括しふりかえるメルマガをお届け。(写真:ScanNetSecurity 永世名誉編集長 りく)

×