CVE-2026-87022 | Apache Tomcat up to 11.0.25 WebSocket Message input validation
A vulnerability was found in Apache Tomcat up to 7.0.109/8.5.100/9.0.121/10.1.59/11.0.25 and classified as critical. Impacted is an unknown function of the component WebSocket Message Handler. The manipulation results in improper input validation.
This vulnerability is known as CVE-2026-87022. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.VulDB Recent EntriesRead More