CVE-2026-86243
EUVD-2026-8526723.09.2026, 13:17
Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected. Users are recommended to upgrade to version 1.3.9 or 2.0.16, which fix the issue.Enginsight
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
| Vendor | Product | Version | Source |
|---|---|---|---|
| apache | tomcat_native | 2.0.0 ≤ 𝑥 ≤ 2.0.15 | CNA |
| apache | tomcat_native | 1.3.0 ≤ 𝑥 ≤ 1.3.8 | CNA |
Debian Releases
Common Weakness Enumeration