Apache Tomcat WebSocket Authentication Header Exposure Vulnerability

Vulnerability

A vulnerability exists in Apache Tomcat's WebSocket implementation, where the HTTP authentication header can be exposed to unintended hosts during the authentication process. This issue affects Apache Tomcat versions 11.0.0-M1 prior to 11.0.21, 10.1.0-M1 prior to 10.1.54, 9.0.2 prior to 9.0.117, 8.5.24 prior to 8.5.100, and 7.0.83 prior to 7.0.109. Users of these versions are advised to upgrade to Tomcat 11.0.22, 10.1.55, or 9.0.118, which address this vulnerability.

Impact

Exploitation of this vulnerability could lead to the unintended exposure of HTTP authentication credentials to a redirect target host during WebSocket communication.

Remediation

Users should upgrade to Apache Tomcat 11.0.22 or later, 10.1.55 or later, or 9.0.118 or later.

Added: May 12, 2026, 4:20 PM
Updated: May 12, 2026, 4:20 PM

Vulnerability Rating

Custom Algorithm
spread
8.8
impact
2.5
exploitability
7.6
remediation
7.7
relevance
7.7
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.