Логотип exploitDog
bind:"CVE-2026-24733"
Консоль
Логотип exploitDog

exploitDog

bind:"CVE-2026-24733"

Количество 9

Количество 9

ubuntu логотип

CVE-2026-24733

около 1 месяца назад

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.

CVSS3: 3.7
EPSS: Низкий
redhat логотип

CVE-2026-24733

около 1 месяца назад

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-24733

около 1 месяца назад

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2026-24733

около 1 месяца назад

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did ...

CVSS3: 3.7
EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0922-1

8 дней назад

Security update for tomcat

EPSS: Низкий
github логотип

GHSA-qq5r-98hh-rxc9

около 1 месяца назад

Apache Tomcat - Security constraint bypass with HTTP/0.9

EPSS: Низкий
suse-cvrf логотип

openSUSE-SU-2026:20350-1

14 дней назад

Security update for tomcat

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0890-1

13 дней назад

Security update for tomcat10

EPSS: Низкий
suse-cvrf логотип

SUSE-SU-2026:0877-1

14 дней назад

Security update for tomcat11

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2026-24733

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.

CVSS3: 3.7
0%
Низкий
около 1 месяца назад
redhat логотип
CVE-2026-24733

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.

CVSS3: 5.3
0%
Низкий
около 1 месяца назад
nvd логотип
CVE-2026-24733

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.

CVSS3: 3.7
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2026-24733

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did ...

CVSS3: 3.7
0%
Низкий
около 1 месяца назад
suse-cvrf логотип
SUSE-SU-2026:0922-1

Security update for tomcat

0%
Низкий
8 дней назад
github логотип
GHSA-qq5r-98hh-rxc9

Apache Tomcat - Security constraint bypass with HTTP/0.9

0%
Низкий
около 1 месяца назад
suse-cvrf логотип
openSUSE-SU-2026:20350-1

Security update for tomcat

14 дней назад
suse-cvrf логотип
SUSE-SU-2026:0890-1

Security update for tomcat10

13 дней назад
suse-cvrf логотип
SUSE-SU-2026:0877-1

Security update for tomcat11

14 дней назад

Уязвимостей на страницу