Insufficient Session Expiration in Apache Tomcat Affects WebSocket Connections
CVE-2026-73180
Currently unrated
What is CVE-2026-73180?
The Apache Tomcat framework exhibits an insufficient session expiration vulnerability whereby an authenticated HTTP session may alter its session ID without terminating the established WebSocket connection. This behavior conflicts with the Jakarta WebSocket specification, allowing potentially unauthorized access to persisted WebSocket sessions even after the underlying HTTP session has ended. It is imperative for users of affected versions to upgrade to the latest releases—version 11.0.25, 10.1.58, or 9.0.121—to remediate this issue effectively.
Affected Version(s)
Apache Tomcat 11.0.0-M1 <= 11.0.24
Apache Tomcat 10.1.0-M1 <= 10.1.57
Apache Tomcat 9.0.0.M1 <= 9.0.120