CVE-2026-41293
critical · 9.8Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
9.8
CVSS
1.7%
EPSS (exploit prob.)
76th
EPSS percentile
2026-05-12
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-20
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| apache | tomcat | >= 8.5.0, <= 8.5.100 |
| apache | tomcat | >= 9.0.0, < 9.0.118 |
| apache | tomcat | >= 10.0.0, <= 10.0.27 |
| apache | tomcat | >= 10.1.0, < 10.1.55 |
| apache | tomcat | >= 11.0.0, < 11.0.22 |
Check a specific version with /api/v1/cve/match.
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2026-41293