https://seclists.org/oss-sec/2026/q3/909: CVE-2026-87022: Apache Tomcat: WebSocket message smuggling with per-message-deflate
Published Sep 23, 2026
·Updated
Affected Software
5 affected components
Apache Tomcat>=11.0.0-M1<=11.0.25
Apache Tomcat>=10.1.0-M1<=10.1.59
Apache Tomcat>=9.0.0.M1<=9.0.121
Apache Tomcat>=8.5.0<=8.5.100
Apache Tomcat>=7.0.56<=7.0.109
Frequently Asked Questions
1
Which Apache Tomcat release lines and versions are affected?
Affected versions are Tomcat 11.0.0-M1 through 11.0.25, 10.1.0-M1 through 10.1.59, 9.0.0.M1 through 9.0.121, 8.5.0 through 8.5.100, and 7.0.56 through 7.0.109.