https://seclists.org/oss-sec/2026/q2/1069: CVE-2026-50229: Apache Tomcat: XSS in number guess example
Published Jun 29, 2026
·Updated
Affected Software
6 affected components
Apache Tomcat 11.0>=11.0.0-M1<=11.0.22
Apache Tomcat 10.1>=10.1.0-M1<=10.1.55
Apache Tomcat 9.0>=9.0.0.M1<=9.0.118
Apache Tomcat 8.5>=8.5.0<=8.5.100
Apache Tomcat 7.0>=7.0.0<=7.0.109
Apache Tomcat
Frequently Asked Questions
1
What is the severity of CVE-2026-50229?
The severity of CVE-2026-50229 is classified as low.
2
Which versions of Apache Tomcat are affected by CVE-2026-50229?
CVE-2026-50229 affects Apache Tomcat versions 11.0.0-M1 through 11.0.22, 10.1.0-M1 through 10.1.55, 9.0.0.M1 through 9.0.118, 8.5.0 through 8.5.100, and 7.0.0 through 7.0.109.
3
How do I fix CVE-2026-50229?
To fix CVE-2026-50229, you should upgrade to a patched version of Apache Tomcat.
4
What type of vulnerability is CVE-2026-50229?
CVE-2026-50229 is an XSS (Cross-Site Scripting) vulnerability.
5
What happens if CVE-2026-50229 is exploited?
If exploited, CVE-2026-50229 can allow an attacker to execute malicious scripts in the context of the user's browser.