Apache Tomcat: Digest authenticator will authenticate any unknown user
Summary
| CVE | CVE-2026-43512 |
|---|---|
| State | PUBLISHED |
| Assigner | apache |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-05-12 16:16:17 UTC |
| Updated | 2026-05-12 16:37:05 UTC |
| Description | DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0. Older unsupported versions any also be affect Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue. |
Risk And Classification
Problem Types: CWE-592 | CWE-592 CWE-592 DEPRECATED: Authentication Bypass Issues
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Apache Software Foundation | Apache Tomcat | affected 11.0.0-M1 11.0.21 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 10.1.0-M1 10.1.54 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 9.0.0.M1 9.0.117 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 8.5.0 8.5.100 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | affected 7.0.0 7.0.109 semver | Not specified |
| CNA | Apache Software Foundation | Apache Tomcat | unknown 7.0.0 semver | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| lists.apache.org/thread/7x09x7o12solvclslw3sz0288xc8wx73 | [email protected] | lists.apache.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.