CVE-2026-43513

May 12, 2026, 6:17 p.m.

None
No Score

Description

Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

Product(s) Impacted

Vendor Product Versions
Apache
  • Tomcat
  • 11.0.0-M1, 10.1.0-M1, 9.0.0.M1, 8.5.0, 7.0.0, 11.0.22, 10.1.55, 9.0.118

Weaknesses

Common security weaknesses mapped to this vulnerability.

CWE-178
Improper Handling of Case Sensitivity
The product does not properly account for differences in case sensitivity when accessing or determining the properties of a resource, leading to inconsistent results.

*CPE(s)

Affected systems and software identified for this CVE.

Type Vendor Product Version Update Edition Language Software Edition Target Software Target Hardware Other Information
a apache tomcat 11.0.0-M1 11.0.21 / / / / / /
a apache tomcat 10.1.0-M1 10.1.54 / / / / / /
a apache tomcat 9.0.0.M1 9.0.117 / / / / / /
a apache tomcat 8.5.0 8.5.100 / / / / / /
a apache tomcat 7.0.0 7.0.109 / / / / / /
a apache tomcat 11.0.22 / / / / / /
a apache tomcat 10.1.55 / / / / / /
a apache tomcat 9.0.118 / / / / / /

Timeline

Published: May 12, 2026, 4:16 p.m.
Last Modified: May 12, 2026, 6:17 p.m.

Status : Undergoing Analysis

CVE is currently being analyzed by NVD staff, this process results in association of reference link tags, CVSS scores, CWE association, and CPE applicability statements.

More info

*Disclaimer: Some vulnerabilities do not have an associated CPE. To enhance the data, we use AI to infer CPEs based on CVE details. This is an automated process and might not always be accurate.