Apache Tomcat Native TLS Buffer Over-Read (v1.3.0-1.3.8, 2.0.0-2.0.15)
CVE-2026-86243 Published on September 23, 2026
Apache Tomcat Native: DoS via TLS handshake
Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash.
This issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected.
Users are recommended to upgrade to version 1.3.9 or 2.0.16, which fix the issue.
Vulnerability Analysis
CVE-2026-86243 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have no impact on confidentiality and integrity, and a high impact on availability.
Weakness Type
Buffer Over-read
The software reads from a buffer using buffer access mechanisms such as indexes or pointers that reference memory locations after the targeted buffer. This typically occurs when the pointer or its index is incremented to a position beyond the bounds of the buffer or when pointer arithmetic results in a position outside of the valid memory location to name a few. This may result in exposure of sensitive information or possibly a crash.
Products Associated with CVE-2026-86243
Want to know whenever a new CVE is published for Apache Tomcat Native? stack.watch will email you.
Affected Versions
Apache Software Foundation Apache Tomcat Native:- Version 2.0.0, <= 2.0.15 is affected.
- Version 1.3.0, <= 1.3.8 is affected.