Race Condition Vulnerability in Apache Tomcat Affects Unix Domain Socket Access
CVE-2026-65183

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
25 August 2026

What is CVE-2026-65183?

An unauthorized local user can exploit a time-of-check time-of-use (TOCTOU) race condition in Apache Tomcat during the creation of unix domain sockets. This vulnerability allows potential access to these sockets, leading to unauthorized actions or data exposure. Users are advised to secure their systems by upgrading to the patched versions: 11.0.25, 10.1.58, and 9.0.121.

Affected Version(s)

Apache Tomcat 11.0.0-M1 <= 11.0.24

Apache Tomcat 10.1.0-M1 <= 10.1.57

Apache Tomcat 9.0.42 <= 9.0.120

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.