Apache Tomcat Observable Timing Discrepancy Vulnerability in AJP Secret Comparison

Vulnerability

A vulnerability exists in Apache Tomcat due to an observable timing discrepancy when comparing AJP secrets. This flaw allows an attacker on the local network to perform a timing attack to deduce the AJP secret. The vulnerability is present in Apache Tomcat versions 11.0.0-M1 prior to 11.0.21, 10.1.0-M1 prior to 10.1.54, 9.0.0-M1 prior to 9.0.117, 8.5.0 prior to 8.5.100, and 7.0.0 prior to 7.0.109. Older unsupported versions may also be affected.

Impact

Exploitation of this vulnerability could lead to a timing attack, allowing an attacker to infer the AJP secret.

Remediation

Users are advised to upgrade to Apache Tomcat 11.0.22, 10.1.55, or 9.0.118.

Added: May 12, 2026, 4:19 PM
Updated: May 12, 2026, 4:19 PM

Vulnerability Rating

Custom Algorithm
spread
8.8
impact
2.5
exploitability
5.4
remediation
7.7
relevance
8.1
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.