Looking for the vulnerability index of Invicti's legacy products?
Apache Tomcat Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2026-42498 - Vulnerability Database

Apache Tomcat Exposure of Sensitive Information to an Unauthorized Actor Vulnerability - CVE-2026-42498

High
Reference: CVE-2026-42498
Title: Apache Tomcat Exposure of Sensitive Information to an Unauthorized Actor Vulnerability
Overview:

Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21 from 10.1.0-M1 through 10.1.54 from 9.0.2 through 9.0.117 from 8.5.24 through 8.5.100 from 7.0.83 through 7.0.109. Users are recommended to upgrade to version 11.0.22 10.1.55 or 9.0.118 which fix the issue.