Improper Output Encoding in Apache Tomcat Affects Multiple Versions
CVE-2026-34483
Currently unrated
What is CVE-2026-34483?
An improper encoding or escaping of output vulnerability exists in the JsonAccessLogValve component of Apache Tomcat, which can potentially allow attackers to manipulate logged data. This flaw affects specific versions of Apache Tomcat from 11.0.0-M1 through 11.0.20, 10.1.0-M1 through 10.1.53, and 9.0.40 through 9.0.116. Users are encouraged to upgrade to versions 11.0.21, 10.1.54, or 9.0.117 to mitigate the risk.
Affected Version(s)
Apache Tomcat 11.0.0-M1 <= 11.0.20
Apache Tomcat 10.1.0-M1 <= 10.1.53
Apache Tomcat 9.0.40 <= 9.0.116