AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2023-46589.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 0No severity score in this snapshot.
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 02, 2026

Disclosure summary

Improper Input Validation vulnerability in Apache Tomcat. Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82, and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M11 onwards, 10.1.16 onwards, 9.0.83 onwards or 8.5.96 onwards, which fix the issue.

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-fccv-jmmp-qg76

Open original source · Updated Oct 02, 2026

Apache Tomcat Improper Input Validation vulnerability

Source severity: HIGH / 0

EcosystemPackageAffected rangeFirst patched
mavenorg.apache.tomcat:tomcat-catalina>= 11.0.0-M1, < 11.0.0-M1111.0.0-M11
mavenorg.apache.tomcat:tomcat-catalina>= 10.1.0-M1, < 10.1.1610.1.16
mavenorg.apache.tomcat:tomcat-catalina>= 9.0.0-M1, < 9.0.839.0.83
mavenorg.apache.tomcat:tomcat-catalina>= 8.5.0, < 8.5.968.5.96
mavenorg.apache.tomcat.embed:tomcat-embed-core>= 11.0.0-M1, < 11.0.0-M1111.0.0-M11
mavenorg.apache.tomcat.embed:tomcat-embed-core>= 10.1.0-M1, < 10.1.1610.1.16
mavenorg.apache.tomcat.embed:tomcat-embed-core>= 9.0.0-M1, < 9.0.839.0.83
mavenorg.apache.tomcat.embed:tomcat-embed-core>= 8.5.0, < 8.5.968.5.96
mavenorg.apache.tomcat:tomcat-coyote>= 11.0.0-M1, < 11.0.0-M1111.0.0-M11

Original records & references

PUBLISHED 2023-11-28T13:30:23-05:00
MODIFIED 2026-10-02T16:14:55-04:00
INGESTED 2026-10-06T11:45:17-04:00