CVE-2026-73180

Apache Tomcat: Authenticated WebSocket session survives end of HTTP session

Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to be affected: from 8.5.0 through 8.5.100, from 7.0.43 through 7.0.109. Other unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.


We have discovered 5,519 live websites that are affected by CVE-2026-73180.

Run a Free Instant Scan




Affected Software

Product  Apache Tomcat
Category Web Servers
Vulnerable Domains5,519 live websites (77% of Apache Tomcat install base)
Vulnerable Versions
  • from 7.0.43 through 7.0.109
  • from 8.5 through 8.5.100
  • from 9 through 9.0.120
  • from 10.1 through 10.1.57
  • from 11 through 11.0.24
Vulnerable Versions Count277 versions ( 73% of all versions)


Common Weakness Enumeration

CWE-613 Insufficient Session Expiration



Details

  • Published - Aug 25, 2026
  • Updated - Aug 26, 2026

Credits

  • 0xCc.zhang (finder)

Website Distribution by Country

Number of websites using CVE-2026-73180
United States1,815 websites



China1,139 websites
Germany342 websites
France159 websites
Italy157 websites
Brazil115 websites
Hong Kong107 websites
GB104 websites
India101 websites

Website Distribution by TLD

Number of websites using CVE-2026-73180
.com2,364 websites
.cn253 websites
.de226 websites
.net212 websites
.edu199 websites
.org179 websites
.it146 websites
.com.br135 websites
.com.cn96 websites
.fr74 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-73180

Top websites that are affected by CVE-2026-73180. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.edu United States***
**************.com United States**,***
**.***.*****.*****.***.com United States**,***
*****.********.com United States**,***
*********.**********.com United States**,***
**.******.com United States**,***
************.com United States**,***
***.*******.com United States**,***
***.*********.edu United States**,***
******.com China**,***
See full domain list

FAQ

CVE-2026-73180 is Insufficient Session Expiration in Apache Tomcat
A total of 5,519 websites have been identified as vulnerable to CVE-2026-73180, based on global website indexing conducted by WebTechSurvey.
The Apache Tomcat is affected by the CVE-2026-73180 vulnerability.
Apache Tomcat versions up to and including 11.0.24 are vulnerable to CVE-2026-73180.