Intel

AIKIDO-2026-924804

tomcat is vulnerable to Improper Input Validation

Improper Input ValidationCVE-2026-65637 Published 3 days ago

65

Medium Risk

This Affects:

JAVAtomcat
9.0.115 - 9.0.120
Fixed in 9.0.121
10.1.53 - 10.1.57
Fixed in 10.1.59
11.0.20 - 11.0.24
Fixed in 11.0.25
Are you affected? Scan for Free

TL;DR

tomcat does not fully enforce strict SNI checks for HTTP/2 requests that omit an authority. A client can send a no-authority HTTP/2 request and skip the intended host match. That can route the request to the wrong virtual host. The fix requires every HTTP/2 request to provide an authority.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and HTTP/2 is enabled with strict SNI validation.

Background info

tomcat is vulnerable to Improper Input Validation in versions 9.0.115 - 9.0.120, 10.1.53 - 10.1.57 and 11.0.20 - 11.0.24.

How to fix this

Upgrade the org.apache.tomcat:tomcat library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform