Authentication Bypass Vulnerability in Apache Tomcat
CVE-2026-65905

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
25 August 2026

What is CVE-2026-65905?

An authentication bypass vulnerability exists in Apache Tomcat's DIGEST authenticator. If a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window before the specified number of requests (windowSize) are sent, that request could be replayed once while the nonceCount is still valid within the replay window. This issue affects several versions of Apache Tomcat, emphasizing the importance of upgrading to secure versions to mitigate potential security risks.

Affected Version(s)

Apache Tomcat 11.0.0-M1 <= 11.0.24

Apache Tomcat 10.1.0-M1 <= 10.1.57

Apache Tomcat 9.0.0.M1 <= 9.0.120

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

4ra1n, pyn3rd and unam4
.