CVE-2026-55955: Apache Tomcat: EncryptInterceptor not protected against replay attacks
Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.
Users are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, which fixes the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 11.0.23 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 10.1.56 - Upgrade
Upgrade
Apache Tomcatto a version that resolves this vulnerability.Fixed in 9.0.119
Event History
Frequently Asked Questions
What is the severity of CVE-2026-55955?
CVE-2026-55955 has a risk rating of 30, indicating a significant security concern.
How do I fix CVE-2026-55955?
To address CVE-2026-55955, upgrade Apache Tomcat to the latest version that is not affected by this vulnerability.
Which versions of Apache Tomcat are affected by CVE-2026-55955?
CVE-2026-55955 affects Apache Tomcat versions from 11.0.0-M1 through 11.0.22, 10.1.0-M1 through 10.1.55, 9.0.13 through 9.0.18, 8.5.38 through 8.5.100, and earlier.
What kind of vulnerability is CVE-2026-55955?
CVE-2026-55955 is classified as an Improper Authentication vulnerability that allows replay attacks.
Is there a workaround for CVE-2026-55955?
There are currently no recommended workarounds; upgrading to a secure version is the best mitigation.