CVE-2026-50229General(apache / tomcat)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-80

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tomcat

Threat summary

  • 10 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • General: 8 classified signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-07-07); latest day: 1
  • 10 total mentions across 6 days

Affected systems

Vendors
Products
tomcat

Deep dive

Activity timeline10 mentions / 6d
01223Mentions · 2026-06-30: 2Mentions · 2026-07-04: 1Mentions · 2026-07-05: 2Mentions · 2026-07-06: 1Mentions · 2026-07-07: 3Mentions · 2026-07-14: 1Technical Details · 2026-06-30: 2Technical Details · 2026-07-14: 106-3007-0407-0507-0607-0707-14
Signal classification2 categories
General
880.0%
Disclosure
220.0%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-06-302
Disclosure1General1
2026-07-041
General1
2026-07-052
General2
2026-07-061
General1
2026-07-073
General3
2026-07-141
Disclosure1
Full discourse10 posts
  • Yasho@YShahinzadeh
    General

    Amir (@AmirMSafari) and I found a CVE in the latest version of Tomcat. It was an easy bug. It's a winning strategy: 0day discovery -> scanning all BB programs -> easy and certain triage This also works for newcommers, not all 0days are hard to find https://www.herodevs.com/vulnerability-directory/cve-2026-50229?nes-for-apache-tomcat https://t.co/5pccjk5lsd

    Post summary

    The tweet announces the discovery of a CVE in Tomcat and shares a link, but offers no technical details, exploit code, or evidence of active exploitation.

    61701663810.5K
    18.8K followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-50229 - medium 🚨 Apache Tomcat - Cross-Site Scripting > Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnera... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-50229 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2026-50229, a medium‑severity Basic XSS flaw in Apache Tomcat, and links to a library entry, yet it contains no PoC, exploit, patch, or evidence of active exploitation.

    07020121.9K
    1.3K followersView on X
  • Kazuki Omo@omokazuki
    Disclosure

    Apache Tomcatの脆弱性(Important: CVE-2026-55957, Moderate: CVE-2026-55956, Low: CVE-2026-55955, CVE-2026-55276, CVE-2026-53434, CVE-2026-53404, CVE-2026-50229) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #tomcat #mod_jk #apache https://security.sios.jp/vulnerability/tomcat-security-vulnerability-20260630/

    Post summary

    The text announces multiple Apache Tomcat CVEs with associated severity levels and links to a security advisory, but does not provide proof of concept, exploit code, active exploitation reports, or patch information.

    00010149
    369 followersView on X
  • ゆぅさん@YY20424277
    General

    「Apache Tomcatにおける複数の脆弱性(2026年6月29日)(CVE-2026-50229)」をボードに上げるなら1ページでどう書く? 背景/目的/効果の3軸で要約しました。 #セキュリティ #経営報告 ▶ 無料プログラム: https://www.intect-i.jp/local-program/?utm_source=sns&utm_medium=social&utm_campaign=local_program

    Post summary

    The tweet references CVE‑2026‑50229 in Apache Tomcat but offers no technical details, patch information, or evidence of exploitation, serving only as a general mention for board discussion.

    0000057
    841 followersView on X
  • ゆぅさん@YY20424277
    General

    【3軸解説】「Apache Tomcatにおける複数の脆弱性(2026年6月29日)(CVE-2026-50229)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効果の3軸で読み解きました。 #セキュリティ #若手コンサル ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The post offers a high‑level overview of CVE‑2026‑50229, an Apache Tomcat vulnerability, presenting its background, purpose, and effect without mentioning PoCs, exploits, patches, or technical details.

    0000065
    841 followersView on X
  • ゆぅさん@YY20424277
    General

    「Apache Tomcatにおける複数の脆弱性(2026年6月29日)(CVE-2026-50229)」をボードに上げるなら1ページでどう書く? 背景/目的/効果の3軸で要約しました。 #セキュリティ #経営報告 ▶ 無料プログラム: https://www.intect-i.jp/local-program/?utm_source=sns&utm_medium=social&utm_campaign=local_program

    Post summary

    The post references CVE‑2026‑50229 as one of several vulnerabilities in Apache Tomcat but offers no technical, exploit, or mitigation details.

    0000076
    845 followersView on X
  • ゆぅさん@YY20424277
    General

    【3軸解説】「Apache Tomcatにおける複数の脆弱性(2026年6月29日)(CVE-2026-50229)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効果の3軸で読み解きました。 #セキュリティ #若手コンサル ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The tweet is a brief commentary on the announcement of several Apache Tomcat vulnerabilities (CVE‑2026‑50229) with no PoC, exploit, patch, or technical details provided.

    0000078
    845 followersView on X
  • ゆぅさん@YY20424277
    General

    「Apache Tomcatにおける複数の脆弱性(2026年6月29日)(CVE-2026-50229)」をボードに上げるなら1ページでどう書く? 背景/目的/効果の3軸で要約しました。 #セキュリティ #経営報告 ▶ 無料プログラム: https://www.intect-i.jp/local-program/?utm_source=sns&utm_medium=social&utm_campaign=local_program

    Post summary

    The post notes the existence of CVE-2026-50229 but offers no technical detail, mitigation, or proof of exploitation.

    0000058
    845 followersView on X
  • ゆぅさん@YY20424277
    General

    【3軸解説】「Apache Tomcatにおける複数の脆弱性(2026年6月29日)(CVE-2026-50229)」を、背景 / 目的 / 効果 の 3 軸で読み解きます。 背景/目的/効果の3軸で読み解きました。 #セキュリティ #若手コンサル ▶ 無料ツール WR-Analysis: https://www.intect-i.jp/tools/wr-analysis/?utm_source=sns&utm_medium=social&utm_campaign=wr_analysis

    Post summary

    The post offers a high‑level 3‑axis overview of CVE‑2026‑50229 but does not provide PoC, exploitation code, evidence of active attacks, patches, or detailed technical data.

    0000056
    846 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-50229 Cross-Site Scripting (XSS) Vulnerability in Apache Tomcat Example Application https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-50229

    Post summary

    The text merely references a CVE for an XSS flaw in Apache Tomcat’s Example Application, lacking details on exploitation, patching, or proofs of use.

    00000121
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat---

Explore more