ghsa-rv64-5gf8-9qq8
CVSS 7.5 osv_maven
Description
Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.
Timeline
- Published
- unknown
- Last Modified
- unknown
CVSS Details
CVSS details not available.
Affected Products
No product information available.
Weaknesses (CWE)
References
Linked Vulnerabilities
No linked vulnerabilities found.
{
"affected": [
{
"database_specific": {
"source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-rv64-5gf8-9qq8/GHSA-rv64-5gf8-9qq8.json"
},
"package": {
"ecosystem": "Maven",
"name": "org.apache.tomcat:tomcat-catalina",
"purl": "pkg:maven/org.apache.tomcat/tomcat-catalina"
},
"ranges": [
{
"events": [
{
"introduced": "9.0.40"
},
{
"fixed": "9.0.116"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"9.0.100",
"9.0.102",
"9.0.104",
"9.0.105",
"9.0.106",
"9.0.107",
"9.0.108",
"9.0.109",
"9.0.110",
"9.0.111",
"9.0.112",
"9.0.113",
"9.0.115",
"9.0.40",
"9.0.41",
"9.0.43",
"9.0.44",
"9.0.45",
"9.0.46",
"9.0.48",
"9.0.50",
"9.0.52",
"9.0.53",
"9.0.54",
"9.0.55",
"9.0.56",
"9.0.58",
"9.0.59",
"9.0.60",
"9.0.62",
"9.0.63",
"9.0.64",
"9.0.65",
"9.0.67",
"9.0.68",
"9.0.69",
"9.0.70",
"9.0.71",
"9.0.72",
"9.0.73",
"9.0.74",
"9.0.75",
"9.0.76",
"9.0.78",
"9.0.79",
"9.0.80",
"9.0.81",
"9.0.82",
"9.0.83",
"9.0.84",
"9.0.85",
"9.0.86",
"9.0.87",
"9.0.88",
"9.0.89",
"9.0.90",
"9.0.91",
"9.0.93",
"9.0.94",
"9.0.95",
"9.0.96",
"9.0.97",
"9.0.98",
"9.0.99"
]
},
{
"database_specific": {
"source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-rv64-5gf8-9qq8/GHSA-rv64-5gf8-9qq8.json"
},
"package": {
"ecosystem": "Maven",
"name": "org.apache.tomcat:tomcat-catalina",
"purl": "pkg:maven/org.apache.tomcat/tomcat-catalina"
},
"ranges": [
{
"events": [
{
"introduced": "10.1.0-M1"
},
{
"fixed": "10.1.54"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"10.1.0",
"10.1.0-M1",
"10.1.0-M10",
"10.1.0-M11",
"10.1.0-M12",
"10.1.0-M14",
"10.1.0-M15",
"10.1.0-M16",
"10.1.0-M17",
"10.1.0-M2",
"10.1.0-M4",
"10.1.0-M5",
"10.1.0-M6",
"10.1.0-M7",
"10.1.0-M8",
"10.1.1",
"10.1.10",
"10.1.11",
"10.1.12",
"10.1.13",
"10.1.14",
"10.1.15",
"10.1.16",
"10.1.17",
"10.1.18",
"10.1.19",
"10.1.2",
"10.1.20",
"10.1.23",
"10.1.24",
"10.1.25",
"10.1.26",
"10.1.28",
"10.1.29",
"10.1.30",
"10.1.31",
"10.1.33",
"10.1.34",
"10.1.35",
"10.1.36",
"10.1.39",
"10.1.4",
"10.1.40",
"10.1.41",
"10.1.42",
"10.1.43",
"10.1.44",
"10.1.45",
"10.1.46",
"10.1.47",
"10.1.48",
"10.1.49",
"10.1.5",
"10.1.50",
"10.1.52",
"10.1.53",
"10.1.6",
"10.1.7",
"10.1.8",
"10.1.9"
]
},
{
"database_specific": {
"source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-rv64-5gf8-9qq8/GHSA-rv64-5gf8-9qq8.json"
},
"package": {
"ecosystem": "Maven",
"name": "org.apache.tomcat:tomcat-catalina",
"purl": "pkg:maven/org.apache.tomcat/tomcat-catalina"
},
"ranges": [
{
"events": [
{
"introduced": "11.0.0-M1"
},
{
"fixed": "11.0.21"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"11.0.0",
"11.0.0-M1",
"11.0.0-M10",
"11.0.0-M11",
"11.0.0-M12",
"11.0.0-M13",
"11.0.0-M14",
"11.0.0-M15",
"11.0.0-M16",
"11.0.0-M17",
"11.0.0-M18",
"11.0.0-M19",
"11.0.0-M20",
"11.0.0-M21",
"11.0.0-M22",
"11.0.0-M24",
"11.0.0-M25",
"11.0.0-M26",
"11.0.0-M3",
"11.0.0-M4",
"11.0.0-M5",
"11.0.0-M6",
"11.0.0-M7",
"11.0.0-M9",
"11.0.1",
"11.0.10",
"11.0.11",
"11.0.12",
"11.0.13",
"11.0.14",
"11.0.15",
"11.0.18",
"11.0.2",
"11.0.20",
"11.0.3",
"11.0.4",
"11.0.5",
"11.0.6",
"11.0.7",
"11.0.8",
"11.0.9"
]
},
{
"database_specific": {
"source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-rv64-5gf8-9qq8/GHSA-rv64-5gf8-9qq8.json"
},
"package": {
"ecosystem": "Maven",
"name": "org.apache.tomcat:tomcat",
"purl": "pkg:maven/org.apache.tomcat/tomcat"
},
"ranges": [
{
"events": [
{
"introduced": "9.0.40"
},
{
"fixed": "9.0.116"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"9.0.100",
"9.0.102",
"9.0.104",
"9.0.105",
"9.0.106",
"9.0.107",
"9.0.108",
"9.0.109",
"9.0.110",
"9.0.111",
"9.0.112",
"9.0.113",
"9.0.115",
"9.0.40",
"9.0.41",
"9.0.43",
"9.0.44",
"9.0.45",
"9.0.46",
"9.0.48",
"9.0.50",
"9.0.52",
"9.0.53",
"9.0.54",
"9.0.55",
"9.0.56",
"9.0.58",
"9.0.59",
"9.0.60",
"9.0.62",
"9.0.63",
"9.0.64",
"9.0.65",
"9.0.67",
"9.0.68",
"9.0.69",
"9.0.70",
"9.0.71",
"9.0.72",
"9.0.73",
"9.0.74",
"9.0.75",
"9.0.76",
"9.0.78",
"9.0.79",
"9.0.80",
"9.0.81",
"9.0.82",
"9.0.83",
"9.0.84",
"9.0.85",
"9.0.86",
"9.0.87",
"9.0.88",
"9.0.89",
"9.0.90",
"9.0.91",
"9.0.93",
"9.0.94",
"9.0.95",
"9.0.96",
"9.0.97",
"9.0.98",
"9.0.99"
]
},
{
"database_specific": {
"source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-rv64-5gf8-9qq8/GHSA-rv64-5gf8-9qq8.json"
},
"package": {
"ecosystem": "Maven",
"name": "org.apache.tomcat:tomcat",
"purl": "pkg:maven/org.apache.tomcat/tomcat"
},
"ranges": [
{
"events": [
{
"introduced": "10.1.0-M1"
},
{
"fixed": "10.1.54"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"10.1.0",
"10.1.0-M1",
"10.1.0-M10",
"10.1.0-M11",
"10.1.0-M12",
"10.1.0-M14",
"10.1.0-M15",
"10.1.0-M16",
"10.1.0-M17",
"10.1.0-M2",
"10.1.0-M4",
"10.1.0-M5",
"10.1.0-M6",
"10.1.0-M7",
"10.1.0-M8",
"10.1.1",
"10.1.10",
"10.1.11",
"10.1.12",
"10.1.13",
"10.1.14",
"10.1.15",
"10.1.16",
"10.1.17",
"10.1.18",
"10.1.19",
"10.1.2",
"10.1.20",
"10.1.23",
"10.1.24",
"10.1.25",
"10.1.26",
"10.1.28",
"10.1.29",
"10.1.30",
"10.1.31",
"10.1.33",
"10.1.34",
"10.1.35",
"10.1.36",
"10.1.39",
"10.1.4",
"10.1.40",
"10.1.41",
"10.1.42",
"10.1.43",
"10.1.44",
"10.1.45",
"10.1.46",
"10.1.47",
"10.1.48",
"10.1.49",
"10.1.5",
"10.1.50",
"10.1.52",
"10.1.53",
"10.1.6",
"10.1.7",
"10.1.8",
"10.1.9"
]
},
{
"database_specific": {
"source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-rv64-5gf8-9qq8/GHSA-rv64-5gf8-9qq8.json"
},
"package": {
"ecosystem": "Maven",
"name": "org.apache.tomcat:tomcat",
"purl": "pkg:maven/org.apache.tomcat/tomcat"
},
"ranges": [
{
"events": [
{
"introduced": "11.0.0-M1"
},
{
"fixed": "11.0.21"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"11.0.0",
"11.0.0-M1",
"11.0.0-M10",
"11.0.0-M11",
"11.0.0-M12",
"11.0.0-M13",
"11.0.0-M14",
"11.0.0-M15",
"11.0.0-M16",
"11.0.0-M17",
"11.0.0-M18",
"11.0.0-M19",
"11.0.0-M20",
"11.0.0-M21",
"11.0.0-M22",
"11.0.0-M24",
"11.0.0-M25",
"11.0.0-M26",
"11.0.0-M3",
"11.0.0-M4",
"11.0.0-M5",
"11.0.0-M6",
"11.0.0-M7",
"11.0.0-M9",
"11.0.1",
"11.0.10",
"11.0.11",
"11.0.12",
"11.0.13",
"11.0.14",
"11.0.15",
"11.0.18",
"11.0.2",
"11.0.20",
"11.0.3",
"11.0.4",
"11.0.5",
"11.0.6",
"11.0.7",
"11.0.8",
"11.0.9"
]
},
{
"database_specific": {
"source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-rv64-5gf8-9qq8/GHSA-rv64-5gf8-9qq8.json"
},
"package": {
"ecosystem": "Maven",
"name": "org.apache.tomcat.embed:tomcat-embed-core",
"purl": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core"
},
"ranges": [
{
"events": [
{
"introduced": "9.0.40"
},
{
"fixed": "9.0.116"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"9.0.100",
"9.0.102",
"9.0.104",
"9.0.105",
"9.0.106",
"9.0.107",
"9.0.108",
"9.0.109",
"9.0.110",
"9.0.111",
"9.0.112",
"9.0.113",
"9.0.115",
"9.0.40",
"9.0.41",
"9.0.43",
"9.0.44",
"9.0.45",
"9.0.46",
"9.0.48",
"9.0.50",
"9.0.52",
"9.0.53",
"9.0.54",
"9.0.55",
"9.0.56",
"9.0.58",
"9.0.59",
"9.0.60",
"9.0.62",
"9.0.63",
"9.0.64",
"9.0.65",
"9.0.67",
"9.0.68",
"9.0.69",
"9.0.70",
"9.0.71",
"9.0.72",
"9.0.73",
"9.0.74",
"9.0.75",
"9.0.76",
"9.0.78",
"9.0.79",
"9.0.80",
"9.0.81",
"9.0.82",
"9.0.83",
"9.0.84",
"9.0.85",
"9.0.86",
"9.0.87",
"9.0.88",
"9.0.89",
"9.0.90",
"9.0.91",
"9.0.93",
"9.0.94",
"9.0.95",
"9.0.96",
"9.0.97",
"9.0.98",
"9.0.99"
]
},
{
"database_specific": {
"source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-rv64-5gf8-9qq8/GHSA-rv64-5gf8-9qq8.json"
},
"package": {
"ecosystem": "Maven",
"name": "org.apache.tomcat.embed:tomcat-embed-core",
"purl": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core"
},
"ranges": [
{
"events": [
{
"introduced": "10.1.0-M1"
},
{
"fixed": "10.1.54"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"10.1.0",
"10.1.0-M1",
"10.1.0-M10",
"10.1.0-M11",
"10.1.0-M12",
"10.1.0-M14",
"10.1.0-M15",
"10.1.0-M16",
"10.1.0-M17",
"10.1.0-M2",
"10.1.0-M4",
"10.1.0-M5",
"10.1.0-M6",
"10.1.0-M7",
"10.1.0-M8",
"10.1.1",
"10.1.10",
"10.1.11",
"10.1.12",
"10.1.13",
"10.1.14",
"10.1.15",
"10.1.16",
"10.1.17",
"10.1.18",
"10.1.19",
"10.1.2",
"10.1.20",
"10.1.23",
"10.1.24",
"10.1.25",
"10.1.26",
"10.1.28",
"10.1.29",
"10.1.30",
"10.1.31",
"10.1.33",
"10.1.34",
"10.1.35",
"10.1.36",
"10.1.39",
"10.1.4",
"10.1.40",
"10.1.41",
"10.1.42",
"10.1.43",
"10.1.44",
"10.1.45",
"10.1.46",
"10.1.47",
"10.1.48",
"10.1.49",
"10.1.5",
"10.1.50",
"10.1.52",
"10.1.53",
"10.1.6",
"10.1.7",
"10.1.8",
"10.1.9"
]
},
{
"database_specific": {
"source": "https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-rv64-5gf8-9qq8/GHSA-rv64-5gf8-9qq8.json"
},
"package": {
"ecosystem": "Maven",
"name": "org.apache.tomcat.embed:tomcat-embed-core",
"purl": "pkg:maven/org.apache.tomcat.embed/tomcat-embed-core"
},
"ranges": [
{
"events": [
{
"introduced": "11.0.0-M1"
},
{
"fixed": "11.0.21"
}
],
"type": "ECOSYSTEM"
}
],
"versions": [
"11.0.0",
"11.0.0-M1",
"11.0.0-M10",
"11.0.0-M11",
"11.0.0-M12",
"11.0.0-M13",
"11.0.0-M14",
"11.0.0-M15",
"11.0.0-M16",
"11.0.0-M17",
"11.0.0-M18",
"11.0.0-M19",
"11.0.0-M20",
"11.0.0-M21",
"11.0.0-M22",
"11.0.0-M24",
"11.0.0-M25",
"11.0.0-M26",
"11.0.0-M3",
"11.0.0-M4",
"11.0.0-M5",
"11.0.0-M6",
"11.0.0-M7",
"11.0.0-M9",
"11.0.1",
"11.0.10",
"11.0.11",
"11.0.12",
"11.0.13",
"11.0.14",
"11.0.15",
"11.0.18",
"11.0.2",
"11.0.20",
"11.0.3",
"11.0.4",
"11.0.5",
"11.0.6",
"11.0.7",
"11.0.8",
"11.0.9"
]
}
],
"aliases": [
"CVE-2026-34483"
],
"database_specific": {
"cwe_ids": [
"CWE-116"
],
"github_reviewed": true,
"github_reviewed_at": "2026-04-10T21:38:21Z",
"nvd_published_at": "2026-04-09T20:16:24Z",
"severity": "HIGH"
},
"details": "Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116.\n\nUsers are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.",
"id": "GHSA-rv64-5gf8-9qq8",
"modified": "2026-09-10T09:40:56.561226538Z",
"published": "2026-04-09T21:31:30Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-34483"
},
{
"type": "PACKAGE",
"url": "https://github.com/apache/tomcat"
},
{
"type": "WEB",
"url": "https://lists.apache.org/thread/j1w7304yonlr8vo1tkb5nfs7od1y228b"
},
{
"type": "WEB",
"url": "http://www.openwall.com/lists/oss-security/2026/04/09/26"
}
],
"schema_version": "1.9.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
],
"summary": "Apache Tomcat has an Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve"
}