Cross-site scripting in Apache Tomcat - CVE-2026-50229
Published: June 30, 2026
Apache Tomcat
Detailed vulnerability description
The vulnerability allows a remote attacker to execute cross-site scripting.
The vulnerability exists due to cross-site scripting in the number guess example when using wild card property mapping that exposes internal properties to clients. A remote attacker can supply crafted input that is reflected through exposed properties to execute cross-site scripting.
The issue is limited to the number guess example application.
How to mitigate CVE-2026-50229
Sources
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.56
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.23
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.119
- https://github.com/apache/tomcat/commit/0d5bdd5b0dd964e9f73e530b7d753462b9bfd1d0