CVE-2026-86243: Apache Tomcat Native: DoS via TLS handshake
Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash.
This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected.
Users are recommended to upgrade to version 1.3.9 or 2.0.16, which fix the issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Apache Tomcat Nativeto a version that resolves this vulnerability.Fixed in 1.3.9 - Upgrade
Upgrade
Apache Tomcat Nativeto a version that resolves this vulnerability.Fixed in 2.0.16
Event History
Frequently Asked Questions
Which deployments should be prioritized for remediation?
Prioritize Apache Tomcat Native installations running versions 2.0.0 through 2.0.15 or 1.3.0 through 1.3.8 that handle TLS handshakes. Earlier unsupported versions may also be affected.
What must an attacker do to trigger the issue?
A malicious user can trigger the buffer over-read during the TLS handshake, leading to a JVM crash and denial of service.
How can I determine whether my installation is affected, and what version fixes it?
Check the installed Apache Tomcat Native version. Upgrade the 1.3.x branch to 1.3.9 or the 2.0.x branch to 2.0.16; these versions fix the issue.