https://seclists.org/oss-sec/2026/q2/496: CVE-2026-43513: Apache Tomcat: LockOutalm tats user names as case-sensitive
Published May 12, 2026
·Updated
Affected Software
2 affected components
Apache Tomcat>=11.0.0-M1<=11.0.21, >=10.1.0-M1<=10.1.54, >=9.0.0.M1<=9.0.117, >=8.5.0<=8.5.100, >=7.0.0<=7.0.109
Apache Tomcat
Frequently Asked Questions
1
What is the severity of CVE-2026-43513?
The severity of CVE-2026-43513 is classified as low.
2
Which versions of Apache Tomcat are affected by CVE-2026-43513?
CVE-2026-43513 affects Apache Tomcat versions 11.0.0-M1 through 11.0.21, 10.1.0-M1 through 10.1.54, 9.0.0.M1 through 9.0.117, 8.5.0 through 8.5.100, and 7.0.0 through 7.0.109.
3
How do I fix CVE-2026-43513?
To fix CVE-2026-43513, upgrade to a version of Apache Tomcat that is not affected, such as the latest stable release.
4
What does CVE-2026-43513 affect in Apache Tomcat?
CVE-2026-43513 affects the case sensitivity of user names when using the LockOutRealm feature.
5
Is CVE-2026-43513 a critical vulnerability?
No, CVE-2026-43513 is considered low severity and is not classified as a critical vulnerability.