THREATOPS
THREAT OPSThreat News › CVE-2026-73180: Apache Tomcat: Authenticated WebSocket session survives end of HTTP session

CVE-2026-73180: Apache Tomcat: Authenticated WebSocket session survives end of HTTP session

medoss_secPublished 2026-08-26

<p>Posted by Mark Thomas on Aug 25</p>Severity: low<br /> <br /> Affected versions:<br /> <br /> - Apache Tomcat 11.0.0-M1 through 11.0.24<br /> - Apache Tomcat 10.1.0-M1 through 10.1.57<br /> - Apache Tomcat 9.0.0.M1 through 9.0.120<br /> - Apache Tomcat 8.5.0 through 8.5.100<br /> - Apache Tomcat 7.0.43 through 7.0.109<br /> - Apache Tomcat before 7.0.43 unaffected<br /> <br /> Description:<br /

Indicators of compromise

Original source: https://seclists.org/oss-sec/2026/q3/588