All vulnerabilities

CVE-2026-43514

Apache Tomcat - AJP secret compared in non-constant time

Description

Versions Affected: Apache Tomcat 11.0.0-M1 to 11.0.21 Apache Tomcat 10.1.0-M1 to 10.1.54 Apache Tomcat 9.0.0.M1 to 9.0.117 Older, unsupported versions may also be affected

Description: The AJP secret was compared in non-constant time allowing an attacker on the local network to mount a timing attack to determine the AJP secret.

Mitigation: Users of the affected versions should apply one of the following mitigations:

  • Upgrade to Apache Tomcat 11.0.22 or later
  • Upgrade to Apache Tomcat 10.1.55 or later
  • Upgrade to Apache Tomcat 9.0.118 or later

Patch Available

Fix available through Seal Security. No upgrade required, protect your application instantly.

Fix without upgrading
Score
3.7
Severity
Low
Ecosystem
Java
Publish Date
May 12, 2026
Modified Date
May 22, 2026
Score Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Affected Versions