Intel

AIKIDO-2026-433748

tomcat-catalina-ha is vulnerable to Insufficient Session Expiration

Insufficient Session ExpirationCVE-2026-73180 Published 3 days ago

68

Medium Risk

This Affects:

JAVAtomcat-catalina-ha
7.0.43 - 9.0.120
Fixed in 9.0.121
10.1.0 - 10.1.57
Fixed in 10.1.59
11.0.0 - 11.0.24
Fixed in 11.0.25
Are you affected? Scan for Free

TL;DR

tomcat-catalina-ha keeps the WebSocket bindings of a clustered HTTP session under the previous session ID when that ID changes. A WebSocket opened under the authenticated session is then not closed once the HTTP session ends. That leaves an authenticated channel open past the HTTP session lifetime. The fix tracks the session ID change so the WebSocket is closed with the HTTP session.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and a WebSocket is opened under an authenticated HTTP session whose session ID is later changed.

Background info

tomcat-catalina-ha is vulnerable to Insufficient Session Expiration in versions 7.0.43 - 9.0.120, 10.1.0 - 10.1.57 and 11.0.0 - 11.0.24.

How to fix this

Upgrade the org.apache.tomcat:tomcat-catalina-ha library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform