Apache Tomcat - Cross-Site Scripting
CVE-2026-50229
Verified
Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.
Severity
Medium
Exploit Probability
4%
Affected Product
tomcat
Published Date
July 7, 2026
Template Author
yshahinzadeh, amirmsafari
CVE-2026-50229.yaml
5.0Severity
CVSS Metrics
CVE ID:
cve-2026-50229
CWE ID:
cwe-80
Remediation Steps
Upgrade to versions 11.0.23, 10.1.56, or 9.0.119 or later.