Bug 2476512 (CVE-2026-43514)

Summary: CVE-2026-43514 tomcat-coyote: Apache Tomcat: Information disclosure via AJP secret timing discrepancy
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: aakkiang, aschwart, asoldano, aszczucz, bbaranow, bmaxwell, boliveir, bstansbe, cfu, csutherl, dhanak, dlofthou, drichtar, drosa, dsoumis, edewata, gkimetto, gmalinko, ibek, istudens, ivassile, iweiss, janstey, jclere, jmagne, jrokos, jwon, mfargett, mharmsen, mnovotny, mosmerov, mposolda, msvehla, nwallace, pberan, pdelbell, pesilva, pjindal, plodge, pmackay, prisingh, rhel-process-autobot, rmartinc, rmaucher, rstancel, rstepani, sausingh, sdawley, skhandel, smaestri, snegrini, ssilvert, sthorger, szappis, taherrin, thjenkin, vchlup, vdosoudi, vmuzikar, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in Apache Tomcat. The AJP secret was comparable in non-constant time, allowing an attacker on the local network to mount a timing attack to determine the AJP secret, which may lead to unauthorized access or other security bypasses.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2486946, 2486947, 2486948    
Bug Blocks:    

Description OSIDB Bzimport 2026-05-12 16:01:51 UTC
Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Older unsupported versions may also be affected.

Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.