Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-86243— Apache Tomcat Native: DoS via TLS handshake

Quick assessment

Affected
Apache Software Foundation Apache Tomcat Native
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versio

AI Predicted 5.9 Difficulty: Easy
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-86243

Vulnerability Information

Shenlong is analyzing...


Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Apache Tomcat Native: DoS via TLS handshake
Source: CVE Program / CVE List V5
Vulnerability Description
Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected. Users are recommended to upgrade to version 1.3.9 or 2.0.16, which fix the issue.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
缓冲区上溢读取
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Apache Software Foundation Apache Tomcat Native 2.0.0 ~ 2.0.15 -

II. Public POCs for CVE-2026-86243

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-86243

登录查看更多情报信息。

Mailing List Discussions for CVE-2026-86243 (1)

Same Patch Batch · Apache Software Foundation · 2026-09-23 · 25 CVEs total

CVE-2026-31377 7.5 HIGH Apache Doris: Improper Authentication Allows Unauthorized Access to FE Meta Service
CVE-2026-75973 Apache Tomcat: Cross-context authentication mix-up with Jakarta Authentication configured
CVE-2026-82331 Apache BuildStream: tar source extraction escape
CVE-2026-73192 Apache Sling XSS: XSS possible through XSSAPI.getValidHref()
CVE-2026-92001 Apache Sling XSS: Missing parser resource limits
CVE-2026-91999 Apache Sling XSS: Improper escaping in the XSS Webconsole plugin
CVE-2026-91852 Apache Sling XSS: CWE-79 multiple raw-string break-outs and ReDOS in XSSImpl
CVE-2026-96443 Apache Doris: JDBC driver URL validation bypass leads to remote code execution
CVE-2026-91928 Apache Sling XSS: Sanitizer bypass, uncontrolled resource consumption and failure pf prote
CVE-2026-94251 Apache Sling Security Bundle: ContentDispositionFilter mediates only one address/API shape
CVE-2026-94243 Apache Sling Security Bundle: RefererFilter accepts weaker-than-origin evidence
CVE-2026-73581 Apache Tomcat: OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate us
CVE-2026-86247 Apache Tomcat Native: Client certificate requirements can be down-graded
CVE-2026-76183 Apache Tomcat: Bypass of security constraints for WebSocket endpoints
CVE-2026-77756 Apache Tomcat: Transfer-Encoding honored for HTTP/1.0 requests
CVE-2026-77762 Apache Tomcat: Stale HPACK emitter injects trailers into recycled pooled Request
CVE-2026-77791 Apache Tomcat: DoS via busy wait during WebSocket close
CVE-2026-78383 Apache Tomcat: AJP DoS via missing request body
CVE-2026-78437 Apache Tomcat: HTTP/2 DoS via malformed request
CVE-2026-79677 Apache Tomcat: WebSocket DoS due to lost asynchronous write timeout

Showing top 20 of 25 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2026-86243

No comments yet


Leave a comment