Improper Length Parameter Handling in Apache Tomcat WebSocket
CVE-2026-87022
Currently unrated
What is CVE-2026-87022?
This vulnerability in Apache Tomcat results from an improper handling of the length parameter inconsistency, enabling WebSocket message smuggling when using the per-message-deflate feature. It affects a range of versions, including several that have reached their end of service, necessitating an upgrade to secured versions 11.0.26, 10.1.60, or 9.1.22 to mitigate any risks associated with this flaw.
Affected Version(s)
Apache Tomcat 11.0.0-M1 <= 11.0.25
Apache Tomcat 10.1.0-M1 <= 10.1.59
Apache Tomcat 9.0.0.M1 <= 9.0.121