---
id: CVE-2026-50229
title: >-
  Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
  vulnerability in the number guess example for Apache Tomcat.


  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from
  10.1.0-M1 through 10.1.55,…
summary: >-
  Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)
  vulnerability in the number guess example for Apache Tomcat.


  This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from
  10.1.0-M1 through 10.1.55,…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-80
  - CWE-79
vendor: apache
product: tomcat
affected:
  - tomcat <= 7.0.109
  - 'tomcat >= 8.5.0, <= 8.5.100'
  - 'tomcat >= 9.0.0, < 9.0.119'
  - 'tomcat >= 10.1.0, < 10.1.56'
  - 'tomcat >= 11.0.0, < 11.0.23'
patched:
  - tomcat 11.0.23
published: '2026-06-29'
updated: '2026-07-02'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-50229'
references:
  - url: 'https://lists.apache.org/thread/wlt2no8bw45zl1w8byop4zfqphldf5j0'
    label: security@apache.org
  - url: 'http://www.openwall.com/lists/oss-security/2026/06/29/20'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50229.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-50229'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2494688'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-50229'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-50229'
  - url: 'https://access.redhat.com/errata/RHSA-2026:67163'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68651'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68677'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68680'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68678'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68679'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68659'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68660'
  - url: 'https://access.redhat.com/errata/RHSA-2026:32960'
tags:
  - nvd
  - exploit-available
  - csaf
  - vex
  - red-hat
epss: 0.04091
epssPercentile: 0.90356
ingestedAt: '2026-07-03T13:02:28.097Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/zero-trace7/CVE-2026-50229'
  nuclei:
    - CVE-2026-50229
  checkedAt: '2026-09-26T09:05:47.138Z'
exploitAvailable: true
scores:
  nvd: 6.1
  vendor: 5.4
---

## Overview

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have reached end of support may also be affected.

Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fix the issue.

## Affected

- `tomcat <= 7.0.109`
- `tomcat >= 8.5.0, <= 8.5.100`
- `tomcat >= 9.0.0, < 9.0.119`
- `tomcat >= 10.1.0, < 10.1.56`
- `tomcat >= 11.0.0, < 11.0.23`

## Remediation

Upgrade past the affected range:

- `tomcat 11.0.23`

## Vendor advisories

- **RHSA-2026:67163** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0) · released 2026-09-14 · [advisory](https://access.redhat.com/errata/RHSA-2026:67163)
- **RHSA-2026:68651** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10) · released 2026-09-18 · [advisory](https://access.redhat.com/errata/RHSA-2026:68651)
- **RHSA-2026:68677** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68677)
- **RHSA-2026:68680** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68680)
- **RHSA-2026:68678** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68678)
- **RHSA-2026:68679** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68679)
- **RHSA-2026:68659** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68659)
- **RHSA-2026:68660** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68660)
- **RHSA-2026:32960** · Red Hat · fixed in: Red Hat Hardened Images · released 2026-06-29 · [advisory](https://access.redhat.com/errata/RHSA-2026:32960)
- **Red Hat VEX** · Moderate · affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat JBoss Web Server 5 · no fix planned: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, … · updated 2026-09-25 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-50229.json)
