[SECURITY] CVE-2026-65183 Apache Tomcat - TOCTOU when setting specific permissions for Unix Domain Sockets

Mark Thomas <[email protected]>
Newsgroups gmane.comp.jakarta.tomcat.devel
Message-ID <[email protected]>
CVE-2026-65183 Apache Tomcat - TOCTOU when setting specific permissions 
for Unix Domain Sockets

Severity: Low

Vendor: The Apache Software Foundation

Versions Affected:
Apache Tomcat 11.0.0-M1 to 11.0.24
Apache Tomcat 10.1.0-M1 to 10.1.57
Apache Tomcat 9.0.42 to 9.0.120

Description:
A race condition when creating a Unix Domain Socket allowed an 
unauthorised local user to access the Unix Domain Socket.

Mitigation:
Users of the affected versions should apply one of the following
mitigations:
- Remove the examples web application
- Upgrade to Apache Tomcat 11.0.25
- Upgrade to Apache Tomcat 10.1.59
- Upgrade to Apache Tomcat 9.0.121

Note: This issue was fixed in Apache Tomcat 10.1.58 but the release vote 
for the 10.1.58 release candidate did not pass. Therefore, although 
users must download 10.1.59 to obtain a version that includes a fix for 
this issue, version 10.1.58 is not included in the list of affected 
versions.

History:
2026-08-25 Original advisory

References:
[1] https://tomcat.apache.org/security-11.html
[2] https://tomcat.apache.org/security-10.html
[3] https://tomcat.apache.org/security-9.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.