CVE Explorer
CVE-2026-43512
DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0.
Older unsupported versions any also be affect
Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Apache Tomcat","vendor":"Apache Software Foundation","versions":[{"lessThanOrEqual":"11.0.21","status":"affected","version":"11.0.0-M1","versionType":"semver"},{"lessThanOrEqual":"10.1.54","status":"affected","version":"10.1.0-M1","versionType":"semver"},{"lessThanOrEqual":"9.0.117","status":"affected","version":"9.0.0.M1","versionType":"semver"},{"lessThanOrEqual":"8.5.100","status":"affected","version":"8.5.0","versionType":"semver"},{"lessThanOrEqual":"7.0.109","status":"affected","version":"7.0.0","versionType":"semver"},{"lessThan":"7.0.0","status"…
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:f5fee02cd21e932ad8d473659b38e4190366cf63f7199997b04ea25c09f544ee · sha256:635af7b3b1f23e3a… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":9.8,"baseSeverity":"CRITICAL","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:f5fee02cd21e932ad8d473659b38e4190366cf63f7199997b04ea25c09f544ee · sha256:635af7b3b1f23e3a… · /containers/adp/1/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-592","description":"CWE-592 DEPRECATED: Authentication Bypass Issues","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:f5fee02cd21e932ad8d473659b38e4190366cf63f7199997b04ea25c09f544ee · sha256:635af7b3b1f23e3a… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"url":"http://www.openwall.com/lists/oss-security/2026/05/12/8"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f5fee02cd21e932ad8d473659b38e4190366cf63f7199997b04ea25c09f544ee · sha256:635af7b3b1f23e3a… · /containers/adp/0/references/0
{"tags":["vendor-advisory"],"url":"https://lists.apache.org/thread/7x09x7o12solvclslw3sz0288xc8wx73"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:f5fee02cd21e932ad8d473659b38e4190366cf63f7199997b04ea25c09f544ee · sha256:635af7b3b1f23e3a… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.