Stateward All advisories →
critical
CVE-2026-43512
Maven · org.apache.tomcat.embed:tomcat-embed-core • Maven · org.apache.tomcat:tomcat • Maven · org.apache.tomcat:tomcat-catalina
Summary Apache Tomcat - Digest authenticator will authenticate any unknown user
Severity critical EPSS 0.6% (p42) Also known as GHSA-h6fc-48rj-7qqh#org.apache.tomcat:tomcat, GHSA-h6fc-48rj-7qqh#org.apache.tomcat:tomcat-catalina, GHSA-h6fc-48rj-7qqh#org.apache.tomcat.embed:tomcat-embed-core, BIT-tomcat-2026-43512 Published 2026-05-12
Related advisories CVE-2026-41293 — critical · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2026-43515 — critical · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2025-24813 — critical · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2020-1938 — critical · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2026-41284 — high · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2026-42498 — high · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2026-43513 — high · Maven/org.apache.tomcat.embed:tomcat-embed-coreCVE-2026-34483 — high · Maven/org.apache.tomcat.embed:tomcat-embed-core
Is your project exposed to this? Stateward checks every dependency on every pull request and flags it only if your code actually reaches it.
Check my repo