#3491·grype

FALSE NEGATIVE: Recent Tomcat vulnerabilities are not detected (e.g., CVE-2026-43512)

Author: imperativesCreated Jun 3, 2026Updated Aug 19, 2026
Labelsbugfalse-negativenew-data-sourceecosystem:java

Vulnerability IDs:

  • DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0. Older unsupported versions any also be affect Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue. (CVE-2026-43512)

  • Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue. (CVE-2026-43515)

  • Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue. (CVE-2026-43514)

  • Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue. (CVE-2026-43513)

CVE-2026-41293

Package URL or steps to reproduce: Running gyre tomcat:10.1.54-jre17 should show the matching issue. All of the above CVEs should be present in Tomcat 10.1.54. (cpe:/a:apache:tomcat:10.1.54)

Note: These CVEs were all picked up by Tenable and Trivy (e.g., trivy --scanners vuln image tomcat:10.1.54-jre17)

Environment:

  • Output of grype version: grype 0.113.0
  • OS (e.g: cat /etc/os-release or similar): RHEL and MacOS