Apache Tomcat: WebSocket authentication header exposure (CVE-2026-42498)
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0 through 11.0.21, from 10.1.0 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.
AI Analysis
Technical Summary
This Red Hat security advisory (RHSA-2026:13745) covers a bug fix and enhancement update for Red Hat Hardened Images RPMs, including multiple Apache Tomcat 11 packages. Among the addressed vulnerabilities is CVE-2026-43512, which allows an authentication bypass via DIGEST authentication due to improper handling of unknown users with the password 'null'. The unknown user does not gain roles or impersonate existing users, limiting the impact. Red Hat notes that DIGEST authentication is not commonly enabled by default in production environments. No explicit patch links are provided, but updated RPM versions (tomcat11-11.0.22-0.1.hum1) are available. Other CVEs addressed include CVE-2026-42498, CVE-2026-43514, and CVE-2026-43515. No known exploits in the wild are reported.
Potential Impact
The primary impact is an authentication bypass under specific conditions when DIGEST authentication is enabled in Apache Tomcat 11. An attacker can authenticate as an unknown user by supplying the password 'null'. However, since this unknown user is not associated with any valid roles, the attacker's access remains limited by application authorization constraints. There is no credential theft or impersonation of existing users. The overall impact is medium severity due to the limited scope and the uncommon use of DIGEST authentication in production.
Mitigation Recommendations
Red Hat recommends disabling DIGEST authentication in Apache Tomcat if it is not essential to the environment. This involves modifying the server's authentication configuration to use alternative methods and restarting the service. Applying the updated RPM packages provided in the advisory will address the vulnerabilities. Since this is a security advisory with updated RPMs, a fix is available through these package updates. Users should refer to https://images.redhat.com/ for details on applying the update.
Apache Tomcat: WebSocket authentication header exposure (CVE-2026-42498)
Description
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0 through 11.0.21, from 10.1.0 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118, which fix the issue.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This Red Hat security advisory (RHSA-2026:13745) covers a bug fix and enhancement update for Red Hat Hardened Images RPMs, including multiple Apache Tomcat 11 packages. Among the addressed vulnerabilities is CVE-2026-43512, which allows an authentication bypass via DIGEST authentication due to improper handling of unknown users with the password 'null'. The unknown user does not gain roles or impersonate existing users, limiting the impact. Red Hat notes that DIGEST authentication is not commonly enabled by default in production environments. No explicit patch links are provided, but updated RPM versions (tomcat11-11.0.22-0.1.hum1) are available. Other CVEs addressed include CVE-2026-42498, CVE-2026-43514, and CVE-2026-43515. No known exploits in the wild are reported.
Potential Impact
The primary impact is an authentication bypass under specific conditions when DIGEST authentication is enabled in Apache Tomcat 11. An attacker can authenticate as an unknown user by supplying the password 'null'. However, since this unknown user is not associated with any valid roles, the attacker's access remains limited by application authorization constraints. There is no credential theft or impersonation of existing users. The overall impact is medium severity due to the limited scope and the uncommon use of DIGEST authentication in production.
Mitigation Recommendations
Red Hat recommends disabling DIGEST authentication in Apache Tomcat if it is not essential to the environment. This involves modifying the server's authentication configuration to use alternative methods and restarting the service. Applying the updated RPM packages provided in the advisory will address the vulnerabilities. Since this is a security advisory with updated RPMs, a fix is available through these package updates. Users should refer to https://images.redhat.com/ for details on applying the update.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:13745
- Cve Count
- 4
- Additional Cves
- ["CVE-2026-43512","CVE-2026-43514","CVE-2026-43515"]
- State
- PUBLISHED
Threat ID: 6a32705b0b89be68881d44d0
Added to database: 06/17/2026, 10:00:59 UTC
Last enriched: 08/10/2026, 18:57:45 UTC
Last updated: 09/15/2026, 22:01:34 UTC
Views: 84
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.