A AegiFlow
HIGHCVSS 7.5EPSS 0.4%

CVE-2026-34487

Apache Tomcat vulnerable to Insertion of Sensitive Information into Log File

Published
2026-04-09
Modified
2026-08-12
EPSS percentile
37%
Aliases
GHSA-x4m4-345f-5h5g
Sources
github-advisory

Summary

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue.

Affected packages

EcosystemPackageAffected versionsFixed versions
Mavenorg.apache.tomcat.embed:tomcat-embed-core9.0.117, 10.1.54, 11.0.21
Mavenorg.apache.tomcat:tomcat9.0.117, 10.1.54, 11.0.21
Mavenorg.apache.tomcat:tomcat-tribes9.0.117, 10.1.54, 11.0.21

Remediation: Upgrade to 9.0.117 or later.

References

Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.

EPSS scores provided by the FIRST.org Exploit Prediction Scoring System.