Improper Length Parameter Handling in Apache Tomcat WebSocket
CVE-2026-87022

Currently unrated

Key Information:

Vendor

Apache

Vendor
CVE Published:
23 September 2026

What is CVE-2026-87022?

This vulnerability in Apache Tomcat results from an improper handling of the length parameter inconsistency, enabling WebSocket message smuggling when using the per-message-deflate feature. It affects a range of versions, including several that have reached their end of service, necessitating an upgrade to secured versions 11.0.26, 10.1.60, or 9.1.22 to mitigate any risks associated with this flaw.

Affected Version(s)

Apache Tomcat 11.0.0-M1 <= 11.0.25

Apache Tomcat 10.1.0-M1 <= 10.1.59

Apache Tomcat 9.0.0.M1 <= 9.0.121

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

krsecurity(kongr)
.