Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-65637

Опубликовано: 25 авг. 2026
Источник: redhat
CVSS3: 6.5

Описание

Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

A flaw was found in Apache Tomcat. This improper input validation vulnerability, stemming from an incomplete fix for CVE-2026-32990, allows for an HTTP/2 no-authority bypass of strict Server Name Indication (SNI) validation. This could potentially lead to unauthorized access or misrouting of requests.

Отчет

This Moderate flaw in Apache Tomcat allows an HTTP/2 no-authority bypass of strict Server Name Indication (SNI) validation due to improper input handling. This could lead to requests being misrouted to an unintended virtual host, potentially exposing sensitive information or causing service disruption in specific configurations. The impact is limited as it primarily affects request routing rather than arbitrary code execution.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tomcatUnder investigation
Red Hat Enterprise Linux 10tomcat9Under investigation
Red Hat Enterprise Linux 7tomcatUnder investigation
Red Hat Enterprise Linux 8pki-deps:10.6/pki-servlet-engineUnder investigation
Red Hat Enterprise Linux 8tomcatUnder investigation
Red Hat Enterprise Linux 9tomcatUnder investigation
Red Hat JBoss Web Server 5tomcatOut of support scope
Red Hat JBoss Web Server 6tomcatNot affected
Red Hat JBoss Web Server 7tomcatAffected
Red Hat Hardened Imagestomcat11-main-11.0.25-0.1.hum1FixedRHSA-2026:5603918.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-444
https://bugzilla.redhat.com/show_bug.cgi?id=2524155Apache Tomcat: Apache Tomcat: Improper Input Validation allows HTTP/2 no-authority bypass of strict SNI validation

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
30 дней назад

Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

CVSS3: 9.8
nvd
30 дней назад

Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

CVSS3: 9.8
debian
30 дней назад

Improper Input Validation vulnerability in Apache Tomcat due to incomp ...

CVSS3: 9.8
github
30 дней назад

Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

suse-cvrf
15 дней назад

Security update for tomcat

6.5 Medium

CVSS3