https://seclists.org/oss-sec/2026/q2/498: CVE-2026-43515: Apache Tomcat: Security constraints not corctly applied
Published May 12, 2026
·Updated
Affected Software
1 affected component
Apache Tomcat>=11.0.0-M1<=11.0.21, >=10.1.0-M1<=10.1.54, >=9.0.0.M1<=9.0.117, >=8.5.0<=8.5.100, >=7.0.0<=7.0.109
Frequently Asked Questions
1
What is the severity of CVE-2026-43515?
The severity of CVE-2026-43515 is classified as moderate.
2
Which versions of Apache Tomcat are affected by CVE-2026-43515?
CVE-2026-43515 affects Apache Tomcat versions 11.0.0-M1 through 11.0.21, 10.1.0-M1 through 10.1.54, 9.0.0-M1 through 9.0.117, 8.5.0 through 8.5.100, and 7.0.0 through 7.0.109.
3
How do I fix CVE-2026-43515?
To fix CVE-2026-43515, upgrade to the latest patched version of Apache Tomcat that is not affected.
4
What does CVE-2026-43515 exploit?
CVE-2026-43515 exploits an issue where security constraints are not correctly applied in certain versions of Apache Tomcat.
5
Is CVE-2026-43515 a critical vulnerability?
No, CVE-2026-43515 is classified as a moderate severity vulnerability.