{"id":"CVE-2026-86243","published":"2026-09-23T13:17:30.993","lastModified":"2026-09-23T19:19:41.600","description":"Buffer over-read vulnerability in Apache Tomcat Native during the TLS handshake permits a malicious user to trigger a DoS via a JVM crash.\n\n\n\nThis issue affects Apache Tomcat Native: from 2.0.0 through 2.0.15, from 1.3.0 through 1.3.8. Earlier, unsupported versions may also be affected.\n\n\n\nUsers are recommended to upgrade to version 1.3.9 or 2.0.16, which fix the issue.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cwes":["CWE-126"],"vendors":[],"products":[],"references":[{"url":"https://lists.apache.org/thread/8p4jf02w54m22x0cwpq2x53w3ov8o557","tags":[]},{"url":"http://www.openwall.com/lists/oss-security/2026/09/23/31","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":null}