CVE-2026-65905

Apache Tomcat: Limited replay attack possible with DIGEST authentication

Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that request is replayable once only while the associated nonceCount remains within the replay window.   This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.30 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.


We have discovered 5,640 live websites that are affected by CVE-2026-65905.

Run a Free Instant Scan




Affected Software

Product  Apache Tomcat
Category Web Servers
Vulnerable Domains5,640 live websites (79% of Apache Tomcat install base)
Vulnerable Versions
  • from 7.0.30 through 7.0.109
  • from 8.5 through 8.5.100
  • from 9 through 9.0.120
  • from 10.1 through 10.1.57
  • from 11 through 11.0.24
Vulnerable Versions Count287 versions ( 76% of all versions)


Common Weakness Enumeration

CWE-294 Authentication Bypass by Capture-replay



Details

  • Published - Aug 25, 2026
  • Updated - Aug 26, 2026

Credits

  • 4ra1n, pyn3rd and unam4 (finder)

Website Distribution by Country

Number of websites using CVE-2026-65905
United States1,840 websites



China1,171 websites
Germany344 websites
France167 websites
Italy163 websites
Brazil115 websites
India108 websites
GB107 websites
Hong Kong107 websites

Website Distribution by TLD

Number of websites using CVE-2026-65905
.com2,404 websites
.cn264 websites
.de227 websites
.net218 websites
.edu200 websites
.org181 websites
.it151 websites
.com.br136 websites
.com.cn97 websites
.fr75 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-65905

Top websites that are affected by CVE-2026-65905. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.edu United States***
**************.com United States**,***
**.***.*****.*****.***.com United States**,***
*****.********.com United States**,***
*********.**********.com United States**,***
**.******.com United States**,***
************.com United States**,***
***.*******.com United States**,***
***.*********.edu United States**,***
******.com China**,***
See full domain list

FAQ

CVE-2026-65905 is Authentication Bypass by Capture-replay in Apache Tomcat
A total of 5,640 websites have been identified as vulnerable to CVE-2026-65905, based on global website indexing conducted by WebTechSurvey.
The Apache Tomcat is affected by the CVE-2026-65905 vulnerability.
Apache Tomcat versions up to and including 11.0.24 are vulnerable to CVE-2026-65905.