CVE-2026-55955
Apache Tomcat: EncryptInterceptor not protected against replay attacks
6.5
MEDIUM
CVSS 3.1
EPSS 0.28%
Description
Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component. This issue affects Apache Tomcat: from 11.0.0 through 11.0.22, from 10.1.0 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.23, 10.1.56, 9.0.119, which fixes the issue.
How to fix CVE-2026-55955
To remediate CVE-2026-55955, upgrade the affected package to a fixed version below.
- —upgrade to 9.0.119 or later
Is CVE-2026-55955 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 9.0.119, >= 10.1.0, < 10.1.56, >= 11.0.0, < 11.0.23
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |