Intel

AIKIDO-2026-262210

tomcat-embed-core is vulnerable to Race Condition (TOCTOU)

Race Condition (TOCTOU)CVE-2026-65183 Published Today

53

Medium Risk

This Affects:

JAVAtomcat-embed-core
9.0.42 - 9.0.120
Fixed in 9.0.121
10.1.0 - 10.1.57
Fixed in 10.1.59
11.0.0 - 11.0.24
Fixed in 11.0.25
Are you affected? Scan for Free

TL;DR

tomcat-embed-core has a time-of-check time-of-use race when creating a Unix domain socket. An unauthorized local user can open the socket during the window between permission setup and use. That exposes the Tomcat connector to a local process that should not have it. The fix creates the socket so another local user cannot open it.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and Tomcat creates a Unix domain socket.

Background info

tomcat-embed-core is vulnerable to Race Condition (TOCTOU) in versions 9.0.42 - 9.0.120, 10.1.0 - 10.1.57 and 11.0.0 - 11.0.24.

How to fix this

Upgrade the org.apache.tomcat.embed:tomcat-embed-core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform