公開日:2026/09/24 最終更新日:2026/09/24

JVNVU#94625787
Apache Tomcatにおける複数の脆弱性(2026年9月23日)

概要

The Apache Software Foundationから、Apache Tomcatの15件の脆弱性に対してアドバイザリが公開されました。

影響を受けるシステム

Apache Tomcatのアドバイザリを参照してください。

想定される影響

Apache Tomcatのアドバイザリを参照してください。

対策方法

Apache Tomcatのアドバイザリを参照してください。

ベンダ情報

ベンダ リンク
The Apache Software Foundation [SECURITY] CVE-2026-73581 Apache Tomcat - OpenSSL and OpenSSL-FFM TLS implementations ignore CRLs when certificate uses a keystore
[SECURITY] CVE-2026-75973 Apache Tomcat - Cross-context authentication mix-up with Jakarta Authentication configured
[SECURITY] CVE-2026-76183 Apache Tomcat - Bypass of security constraints for WebSocket endpoints
[SECURITY] CVE-2026-77756 Apache Tomcat - Transfer-Encoding honored for HTTP/1.0 requests
[SECURITY] CVE-2026-77762 Apache Tomcat - Stale HPACK emitter injects trailers into recycled pooled Request
[SECURITY] CVE-2026-77791 Apache Tomcat - DoS via busy wait during WebSocket close
[SECURITY] CVE-2026-78383 Apache Tomcat - AJP DoS via missing request body
[SECURITY] CVE-2026-78437 Apache Tomcat - HTTP/2 DoS via malformed request
[SECURITY] CVE-2026-79677 Apache Tomcat - WebSocket DoS due to lost asynchronous write timeout
[SECURITY] CVE-2026-86243 Apache Tomcat Native - DoS via TLS handshake
[SECURITY] CVE-2026-86246 Apache Tomcat Native - Insecure OpenSSL options enabled
[SECURITY] CVE-2026-86247 Apache Tomcat Native - Client certificate requirements can be down-graded
[SECURITY] CVE-2026-86248 Apache Tomcat - Fix for CVE-2026-34500 was incomplete. OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
[SECURITY] CVE-2026-86350 Apache Tomcat - Regression in fix for CVE-2026-41293 can trigger request header mix-up
[SECURITY] CVE-2026-87022 Apache Tomcat - WebSocket message smuggling with per-message-deflate

参考情報

JPCERT/CCからの補足情報

JPCERT/CCによる脆弱性分析結果

謝辞

関連文書

JPCERT 緊急報告
JPCERT REPORT
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia