Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HApache Tomcat
APPApache9.0.115 – 9.0.121 (excl.)10.1.53 – 10.1.58 (excl.)11.0.20 – 11.0.25 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2025-24813CRITICAL9.8⚠ KEVPL ✓same product
Apache Tomcat: Path Equivalence prowadzący do RCE i ujawnienia danych
CVE-2020-1938CRITICAL9.8⚠ KEVPL ✓same product
Apache Tomcat AJP Connector — odczyt plików i RCE (Ghostcat)
CVE-2016-8735CRITICAL9.8⚠ KEVPL ✓same product
Apache Tomcat RCE przez JmxRemoteLifecycleListener (JMX)
CVE-2026-65182CRITICAL9.1same product
Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint b...
CVE-2026-65905CRITICAL9.8same product
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before wind...