{
  "threat_severity" : "Moderate",
  "public_date" : "2026-05-12T15:26:25Z",
  "bugzilla" : {
    "description" : "tomcat-catalina: Apache Tomcat: Improper Handling of Case Sensitivity in LockOutRealm",
    "id" : "2476520",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=2476520"
  },
  "cvss3" : {
    "cvss3_base_score" : "5.3",
    "cvss3_scoring_vector" : "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N",
    "status" : "verified"
  },
  "cwe" : "CWE-178",
  "details" : [ "Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat.\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.\nOlder unsupported versions may also be affected.\nUsers are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.", "In Apache Tomcat, LockOutRealm mishandled case sensitivity in usernames, resulting in less effective blocking of brute force attacks." ],
  "statement" : "A flaw was found in Apache Tomcat's LockOutRealm. When configured with an underlying Realm where usernames are case-insensitive, the LockOutRealm does not account for case differences, potentially reducing the effectiveness of brute-force protection. Exploitation requires LockOutRealm to be configured with a case-insensitive authentication backend, which is a non-default configuration.",
  "affected_release" : [ {
    "product_name" : "Red Hat JBoss Web Server 7.0.0",
    "release_date" : "2026-07-14T00:00:00Z",
    "advisory" : "RHSA-2026:39189",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:7.0",
    "package" : "tomcat-catalina"
  }, {
    "product_name" : "Red Hat JBoss Web Server 7.0 on RHEL 10",
    "release_date" : "2026-07-14T00:00:00Z",
    "advisory" : "RHSA-2026:39188",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el10",
    "package" : "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el10jws"
  }, {
    "product_name" : "Red Hat JBoss Web Server 7.0 on RHEL 8",
    "release_date" : "2026-07-14T00:00:00Z",
    "advisory" : "RHSA-2026:39188",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el8",
    "package" : "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el8jws"
  }, {
    "product_name" : "Red Hat JBoss Web Server 7.0 on RHEL 9",
    "release_date" : "2026-07-14T00:00:00Z",
    "advisory" : "RHSA-2026:39188",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:7.0::el9",
    "package" : "jws7-tomcat-0:11.0.21-5.redhat_00004.1.el9jws"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat JBoss Web Server 6",
    "fix_state" : "Affected",
    "package_name" : "tomcat-catalina",
    "cpe" : "cpe:/a:redhat:jboss_enterprise_web_server:6"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2026-43513\nhttps://nvd.nist.gov/vuln/detail/CVE-2026-43513\nhttps://lists.apache.org/thread/ytjcgldshj73lcnd1sh95od5hrghwogp" ],
  "name" : "CVE-2026-43513",
  "mitigation" : {
    "value" : "This vulnerability only affects Tomcat deployments using the LockOutRealm with a case-insensitive authentication backend. Deployments not using LockOutRealm or using case-sensitive authentication backends are not affected.",
    "lang" : "en:us"
  },
  "csaw" : false
}