CVE-2026-50229: Apache Tomcat: XSS in number guess example
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/tomcat9to a version that resolves this vulnerability.Fixed in 9.0.118-0+deb11u1Fixed in 9.0.70-2Fixed in 9.0.95-1Fixed in 9.0.118-1 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.23 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.56 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.119
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50229?
CVE-2026-50229 has a risk rating of 30, indicating a significant security concern.
How do I fix CVE-2026-50229?
To fix CVE-2026-50229, upgrade Apache Tomcat to a version beyond 11.0.22, 10.1.55, 9.0.118, or 8.5.100.
What types of applications are affected by CVE-2026-50229?
CVE-2026-50229 affects applications utilizing the number guess example within various versions of Apache Tomcat.
What specific vulnerability does CVE-2026-50229 describe?
CVE-2026-50229 describes an improper neutralization of script-related HTML tags, leading to a cross-site scripting (XSS) vulnerability.
Is CVE-2026-50229 present in all Apache Tomcat versions?
No, CVE-2026-50229 is present in specific versions of Apache Tomcat ranging from 8.5.0 to 11.0.22.