This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120.
Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 25 Aug 2026 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58, 9.0.121, which fixes the issue. | |
| Title | Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets | |
| Weaknesses | CWE-367 | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-08-25T21:44:49.363Z
Reserved: 2026-07-21T18:45:53.137Z
Link: CVE-2026-65183
No data.
Status : Received
Published: 2026-08-25T22:17:05.050
Modified: 2026-08-25T22:17:05.050
Link: CVE-2026-65183
No data.
OpenCVE Enrichment
Updated: 2026-08-26T01:30:16Z
-
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition