Incomplete Cleanup Vulnerability in Apache Tomcat Product by Apache
CVE-2026-78437

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-78437?

An incomplete cleanup vulnerability exists in the Apache Tomcat application that could potentially lead to failures when processing requests under specific timing conditions. This issue could allow a malformed request from one user to impact another user's request. It affects various versions of Apache Tomcat, requiring immediate attention and the application of security updates to ensure continual protection. Users should upgrade to Apache Tomcat versions 11.0.26, 10.1.60, or 9.0.122 to mitigate this vulnerability.

Affected Version(s)

Apache Tomcat 11.0.19 <= 11.0.25

Apache Tomcat 10.1.53 <= 10.1.59

Apache Tomcat 9.0.116 <= 9.0.121

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.