CVE-2026-87022
Last modified
CVE-2026-87022 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling when per-message-deflate is used. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOS at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.56 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.1.22, which fix the issue..
Description
Improper handling of length parameter inconsistency vulnerability in Apache Tomcat allows WebSocket message smuggling when per-message-deflate is used. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.25, from 10.1.0-M1 through 10.1.59, from 9.0.0.M1 through 9.0.121. The following versions were EOS at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.56 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.26, 10.1.60 or 9.1.22, which fix the issue.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Apache Software Foundation | Apache Tomcat | >= 11.0.0-M1, <= 11.0.25; >= 10.1.0-M1, <= 10.1.59; >= 9.0.0.M1, <= 9.0.121; >= 8.5.0, <= 8.5.100; >= 7.0.56, <= 7.0.109 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-87022?
How severe is CVE-2026-87022?
How do I fix CVE-2026-87022?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-87016Open WebUI is an extensible, feature-rich, and user-friendly…8.1
- CVE-2026-87017Open WebUI is an extensible, feature-rich, and user-friendly…4.3
- CVE-2026-87019Tanium addressed an improper access controls vulnerability i…4.3
- CVE-2026-8702The GBI To Print plugin for WordPress is vulnerable to Store…6.4
- CVE-2026-87020An integer overflow in a specified pitch and buffer-size com…8.1
- CVE-2026-87021Tanium addressed an unauthorized code execution vulnerabilit…7.2
- CVE-2026-87023Tanium addressed a path traversal vulnerability in Comply.8.5
- CVE-2026-87024Tanium addressed a SQL injection vulnerability in Asset.7.2
- CVE-2026-87025Tanium addressed an improper access controls vulnerability i…5.4
- CVE-2026-87026Tanium addressed an improper access controls vulnerability i…3.8
- CVE-2026-87028Concrete CMS 9 through 9.5.3 did not confirm that a board In…6.5
- CVE-2026-8703The Endless Scroll plugin for WordPress is vulnerable to Sto…6.4
Are you affected by CVE-2026-87022?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
