Executive brief
Apache Tomcat is a widely-used application server that hosts Java web applications. An improper input validation vulnerability stemming from an incomplete fix for a previous security issue could allow attackers to bypass protections and compromise the integrity or availability of hosted applications and services.
Technical details
This vulnerability is an improper input validation flaw in Apache Tomcat that arose from an incomplete fix to CVE-2026-32990. The issue affects Tomcat versions 11.0.20–11.0.24, 10.1.53–10.1.57, and 9.0.115–9.0.120. The vulnerability is exploitable via network attack without requiring authentication or special privileges. An attacker can leverage the insufficient input validation to bypass existing security controls and achieve unauthorized access or denial of service. Patches are available in versions 11.0.25, 10.1.58, and 9.0.121.
Affected products
- Apache Tomcat 11.0.20–11.0.24, 10.1.53–10.1.57, 9.0.115–9.0.120
Timeline
- 2026-08-25: disclosed