CVE-2026-86243: Apache Tomcat Native: DoS via TLS handshake
CVE-2026-86243 buffer over-read in Apache Tomcat Native can crash the JVM during TLS handshake.
Apache rates CVE-2026-86243 important. A buffer over-read in Apache Tomcat Native during the TLS handshake lets a malicious user crash the JVM and cause a denial of service. Affected releases are 2.0.0 through 2.0.15 and 1.3.0 through 1.3.8; earlier unsupported versions may also be affected. The disclosure does not report active exploitation.
- Important-severity buffer over-read during the TLS handshake
- A malicious handshake can crash the JVM and cause DoS
- Affects Tomcat Native 1.3.0–1.3.8 and 2.0.0–2.0.15
- Disclosure does not report observed exploitation
Vulnerabilities mentionedAll →
- CVE-2026-862437.5—TLS Handshake Buffer Over-Read Enables Remote DoS in Apache Tomcat Nativepublished · Apache Software Foundation Apache Tomcat Native
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-86243 | TLS Handshake Buffer Over-Read Enables Remote DoS in Apache Tomcat Native Apache Tomcat Native (tc-native), the APR/OpenSSL-based connector library used with Apache Tomcat, contains a buffer over-read (CWE-126) in its handling of TLS handshakes. An unauthenticated remote attacker can trigger the flaw simply by sending a maliciously crafted TLS handshake to a server using the native connector, causing the JVM to crash and taking the affected application offline. The impact is denial of service only — the CVSS 3.1 vector (AV:N/AC:L/PR:N, C:N/I:N/A:H) indicates no confidentiality or integrity impact, and it is rated 7.5 (high). All deployments running Tomcat Native 2.0.0–2.0.15 or 1.3.0–1.3.8 (and possibly older unsupported releases) are affected. No public proof-of-concept exists, the flaw is not in the CISA Known Exploited Vulnerabilities catalog, and no exploitation has been observed in the wild. |
Posted by Mark Thomas on Sep 23 Severity: important Affected versions: - Apache Tomcat Native 2.0.0 through 2.0.15 - Apache Tomcat Native 1.3.0 through 1.3.8 Description: Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash. This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected. Users are...
This source does not provide full text. Read it at seclists.org.