Input validation error in Apache Tomcat - CVE-2026-87022
Published: September 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to smuggle WebSocket messages.
The vulnerability exists due to improper handling of a length parameter in WebSocket per-message-deflate processing when processing WebSocket messages with per-message-deflate enabled. A remote attacker can send a crafted WebSocket message to smuggle WebSocket messages.
Only WebSocket connections using per-message-deflate are affected.