← All CVEs

CVE-2026-41293

critical · 9.8

Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.

9.8
CVSS
1.7%
EPSS (exploit prob.)
76th
EPSS percentile
2026-05-12
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-20

Affected products

VendorProductAffected versions
apachetomcat>= 8.5.0, <= 8.5.100
apachetomcat>= 9.0.0, < 9.0.118
apachetomcat>= 10.0.0, <= 10.0.27
apachetomcat>= 10.1.0, < 10.1.55
apachetomcat>= 11.0.0, < 11.0.22

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2026-41293