Skip to finding
important · Edge devices

Template syntax in a request path can bypass Tomcat security constraints on WebSocket endpoints.

Affects

Apache Tomcat, a cross-platform Java Servlet and WebSocket application server.

A network client can make Tomcat interpret an attacker-supplied candidate path as an endpoint template and reach a protected WebSocket endpoint without the configured authentication constraint. Apache has published the correction.

Detail and 3 sources
Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Thursday, September 24, 2026