https://seclists.org/oss-sec/2026/q2/497: CVE-2026-43514: Apache Tomcat: AJP sect compad in non-constant time
Published May 12, 2026
·Updated
Affected Software
1 affected component
Apache Tomcat>=11.0.0-M1<=11.0.21, >=10.1.0-M1<=10.1.54, >=9.0.0.M1<=9.0.117, >=8.5.0<=8.5.100, >=7.0.0<=7.0.109, <7.0.0
Frequently Asked Questions
1
What is the severity of CVE-2026-43514?
The severity of CVE-2026-43514 is classified as low.
2
Which versions of Apache Tomcat are affected by CVE-2026-43514?
CVE-2026-43514 affects Apache Tomcat versions 11.0.0-M1 through 11.0.21, 10.1.0-M1 through 10.1.54, 9.0.0.M1 through 9.0.117, 8.5.0 through 8.5.100, and 7.0.0 through 7.0.109.
3
How do I fix CVE-2026-43514?
To fix CVE-2026-43514, upgrade your Apache Tomcat installation to the latest version that is not affected.
4
Is there a workaround for CVE-2026-43514?
There are no specific workarounds for CVE-2026-43514, so upgrading is the recommended approach.
5
What is the impact of CVE-2026-43514 on my system?
CVE-2026-43514 may potentially lead to security risks due to non-constant time comparison vulnerabilities, but its impact is considered low.