HIGH7.5
GHSA-x4m4-345f-5h5g
Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File
Quick fix
GHSA-x4m4-345f-5h5g — org.apache.tomcat:tomcat-tribes: upgrade to the fixed version with the command below.
# pom.xml: bump <version>9.0.117</version> for org.apache.tomcat:tomcat-tribesDetails
Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.
Are you affected?
Enter the version of the package you're using.
Affected packages
Maven/org.apache.tomcat:tomcat-tribes
Introduced in:
9.0.13Fixed in: 9.0.117Fix
# pom.xml: bump <version>9.0.117</version> for org.apache.tomcat:tomcat-tribesMaven/org.apache.tomcat:tomcat-tribes
Introduced in:
10.1.0-M1Fixed in: 10.1.54Fix
# pom.xml: bump <version>10.1.54</version> for org.apache.tomcat:tomcat-tribesMaven/org.apache.tomcat:tomcat-tribes
Introduced in:
11.0.0-M1Fixed in: 11.0.21Fix
# pom.xml: bump <version>11.0.21</version> for org.apache.tomcat:tomcat-tribesMaven/org.apache.tomcat:tomcat
Introduced in:
9.0.13Fixed in: 9.0.117Fix
# pom.xml: bump <version>9.0.117</version> for org.apache.tomcat:tomcatMaven/org.apache.tomcat:tomcat
Introduced in:
10.1.0-M1Fixed in: 10.1.54Fix
# pom.xml: bump <version>10.1.54</version> for org.apache.tomcat:tomcatMaven/org.apache.tomcat:tomcat
Introduced in:
11.0.0-M1Fixed in: 11.0.21Fix
# pom.xml: bump <version>11.0.21</version> for org.apache.tomcat:tomcatMaven/org.apache.tomcat.embed:tomcat-embed-core
Introduced in:
9.0.13Fixed in: 9.0.117Fix
# pom.xml: bump <version>9.0.117</version> for org.apache.tomcat.embed:tomcat-embed-coreMaven/org.apache.tomcat.embed:tomcat-embed-core
Introduced in:
10.1.0-M1Fixed in: 10.1.54Fix
# pom.xml: bump <version>10.1.54</version> for org.apache.tomcat.embed:tomcat-embed-coreMaven/org.apache.tomcat.embed:tomcat-embed-core
Introduced in:
11.0.0-M1Fixed in: 11.0.21Fix
# pom.xml: bump <version>11.0.21</version> for org.apache.tomcat.embed:tomcat-embed-coreReferences
- https://nvd.nist.gov/vuln/detail/CVE-2026-34487[ADVISORY]
- https://github.com/apache/tomcat/commit/301bc6efbf72feb14dacfdfa3f50372182736150[WEB]
- https://github.com/apache/tomcat/commit/5eff2a773b8b728083e5195b3183df1b9e12a03d[WEB]
- https://github.com/apache/tomcat/commit/f593292a082e5ef9336a8db2b4b522f7f3e36976[WEB]
- https://github.com/apache/tomcat[PACKAGE]
- https://lists.apache.org/thread/4xpkwolpkrj8v5xzp5nyovtlqp3y850h[WEB]
- https://tomcat.apache.org/security-10.html[WEB]
- https://tomcat.apache.org/security-11.html[WEB]
- https://tomcat.apache.org/security-9.html[WEB]
- http://www.openwall.com/lists/oss-security/2026/04/09/28[WEB]