CVE-2026-86243 Apache Tomcat Native - DoS via TLS handshake
Severity: Important
Vendor: The Apache Software Foundation
Versions Affected:
Apache Tomcat Native 2.0.0 to 2.0.15
Apache Tomcat Native 1.3.0 to 1.3.8
Older, EOL versions may also be affected
Description:
A buffer over-read vulnerability in Apache Tomcat Native during the TLS
handshaking permits a malicious user to trigger a DoS via a JVM crash.
Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Upgrade to Apache Tomcat Native 2.0.16 or later
- Upgrade to Apache Tomcat Native 1.3.9 or later
History:
2026-09-23 Original advisory
References:
[1] https://tomcat.apache.org/security-native