HIGH 7.5
GHSA-x4m4-345f-5h5g
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
Details
Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven / org.apache.tomcat:tomcat-tribes
Introduced in:
9.0.13 Fixed in: 9.0.117 Fix
# pom.xml: bump <version>9.0.117</version> for org.apache.tomcat:tomcat-tribes Maven / org.apache.tomcat:tomcat-tribes
Introduced in:
10.1.0-M1 Fixed in: 10.1.54 Fix
# pom.xml: bump <version>10.1.54</version> for org.apache.tomcat:tomcat-tribes Maven / org.apache.tomcat:tomcat-tribes
Introduced in:
11.0.0-M1 Fixed in: 11.0.21 Fix
# pom.xml: bump <version>11.0.21</version> for org.apache.tomcat:tomcat-tribes Maven / org.apache.tomcat:tomcat
Introduced in:
9.0.13 Fixed in: 9.0.117 Fix
# pom.xml: bump <version>9.0.117</version> for org.apache.tomcat:tomcat Maven / org.apache.tomcat:tomcat
Introduced in:
10.1.0-M1 Fixed in: 10.1.54 Fix
# pom.xml: bump <version>10.1.54</version> for org.apache.tomcat:tomcat Maven / org.apache.tomcat:tomcat
Introduced in:
11.0.0-M1 Fixed in: 11.0.21 Fix
# pom.xml: bump <version>11.0.21</version> for org.apache.tomcat:tomcat References
- https://nvd.nist.gov/vuln/detail/CVE-2026-34487 [ADVISORY]
- https://github.com/apache/tomcat/commit/301bc6efbf72feb14dacfdfa3f50372182736150 [WEB]
- https://github.com/apache/tomcat/commit/5eff2a773b8b728083e5195b3183df1b9e12a03d [WEB]
- https://github.com/apache/tomcat/commit/f593292a082e5ef9336a8db2b4b522f7f3e36976 [WEB]
- https://github.com/apache/tomcat [PACKAGE]
- https://lists.apache.org/thread/4xpkwolpkrj8v5xzp5nyovtlqp3y850h [WEB]
- https://tomcat.apache.org/security-10.html [WEB]
- https://tomcat.apache.org/security-11.html [WEB]
- https://tomcat.apache.org/security-9.html [WEB]
- http://www.openwall.com/lists/oss-security/2026/04/09/28 [WEB]