logo

Encryption Bypasses and Kubernetes Token Leaks Hit Apache Tomcat

ID: 4cde6080-7166-58b9-97c1-3d6217f3b5c2

STIX ID: report--4cde6080-7166-58b9-97c1-3d6217f3b5c2

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-04-13

Date Updated: 2026-05-05

Author: Ddos

...
...

Apache Tomcat has ten disclosed vulnerabilities across multiple branches (8.5, 9.0, 10.1, 11.0) that include high-impact cryptographic issues (a padding oracle and an EncryptInterceptor bypass), OCSP/client-cert soft-fail logic, exposure of Kubernetes bearer tokens in logs, HTTP request smuggling, open redirect, and JSON logging escape; administrators are advised to upgrade immediately (and update Tomcat Native) to remediate these issues.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.