- CVE ID
- CVE-2026-41293
- CVE Description
- Improper Input Validation vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27.
Older, end of support versions may also be affected.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
- Published
- May 13, 2026
- CVSS Score & Severity
5.3Medium
- CVSS Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
- EPSS Score
- 0.082%
- KEV Status
Not in KEV Catalog: No known exploits
- Vulnerable Methods
org/apache/coyote/http2/HPackHuffman.decode(Ljava/nio/ByteBuffer;ILjava/lang/StringBuilder;)VJVMVulnerable params: 0
org/apache/coyote/http2/HpackDecoder.readHpackString(Ljava/nio/ByteBuffer;)Ljava/lang/String;JVMVulnerable params: 0
- Source
- National Vulnerability Database