Based on the discussion here: https://www.mail-archive.com/dev@tomcat.apache.org/msg136990.html This is similar to 63825 and 63824. The class does neither compare case-insensitively as required by the appropriate RFC not does it compare complete tokens split at the comma.
Fixed in: - master for 9.0.28 onwards - 8.5.x for 8.5.48 onwards - 7.0.x for 7.0.98 onwards