HIGH 7.5
GHSA-x4m4-345f-5h5g
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
Quick fix
GHSA-x4m4-345f-5h5g — org.apache.tomcat:tomcat-tribes: upgrade to the fixed version with the command below.
# pom.xml: bump <version>9.0.117</version> for org.apache.tomcat:tomcat-tribes Details
Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven / org.apache.tomcat:tomcat-tribes
Introduced in:
9.0.13 Fixed in: 9.0.117 Fix
# pom.xml: bump <version>9.0.117</version> for org.apache.tomcat:tomcat-tribes Maven / org.apache.tomcat:tomcat-tribes
Introduced in:
10.1.0-M1 Fixed in: 10.1.54 Fix
# pom.xml: bump <version>10.1.54</version> for org.apache.tomcat:tomcat-tribes Maven / org.apache.tomcat:tomcat-tribes
Introduced in:
11.0.0-M1 Fixed in: 11.0.21 Fix
# pom.xml: bump <version>11.0.21</version> for org.apache.tomcat:tomcat-tribes Maven / org.apache.tomcat:tomcat
Introduced in:
9.0.13 Fixed in: 9.0.117 Fix
# pom.xml: bump <version>9.0.117</version> for org.apache.tomcat:tomcat Maven / org.apache.tomcat:tomcat
Introduced in:
10.1.0-M1 Fixed in: 10.1.54 Fix
# pom.xml: bump <version>10.1.54</version> for org.apache.tomcat:tomcat Maven / org.apache.tomcat:tomcat
Introduced in:
11.0.0-M1 Fixed in: 11.0.21 Fix
# pom.xml: bump <version>11.0.21</version> for org.apache.tomcat:tomcat Maven / org.apache.tomcat.embed:tomcat-embed-core
Introduced in:
9.0.13 Fixed in: 9.0.117 Fix
# pom.xml: bump <version>9.0.117</version> for org.apache.tomcat.embed:tomcat-embed-core Maven / org.apache.tomcat.embed:tomcat-embed-core
Introduced in:
10.1.0-M1 Fixed in: 10.1.54 Fix
# pom.xml: bump <version>10.1.54</version> for org.apache.tomcat.embed:tomcat-embed-core Maven / org.apache.tomcat.embed:tomcat-embed-core
Introduced in:
11.0.0-M1 Fixed in: 11.0.21 Fix
# pom.xml: bump <version>11.0.21</version> for org.apache.tomcat.embed:tomcat-embed-core References
- https://nvd.nist.gov/vuln/detail/CVE-2026-34487 [ADVISORY]
- https://github.com/apache/tomcat/commit/301bc6efbf72feb14dacfdfa3f50372182736150 [WEB]
- https://github.com/apache/tomcat/commit/5eff2a773b8b728083e5195b3183df1b9e12a03d [WEB]
- https://github.com/apache/tomcat/commit/f593292a082e5ef9336a8db2b4b522f7f3e36976 [WEB]
- https://github.com/apache/tomcat [PACKAGE]
- https://lists.apache.org/thread/4xpkwolpkrj8v5xzp5nyovtlqp3y850h [WEB]
- https://tomcat.apache.org/security-10.html [WEB]
- https://tomcat.apache.org/security-11.html [WEB]
- https://tomcat.apache.org/security-9.html [WEB]
- http://www.openwall.com/lists/oss-security/2026/04/09/28 [WEB]