Intel

AIKIDO-2026-983621

tomcat-embed-core is vulnerable to Improper Input Validation

Improper Input ValidationCVE-2026-65637 Published Today

65

Medium Risk

This Affects:

JAVAtomcat-embed-core
9.0.115 - 9.0.120
Fixed in 9.0.121
10.1.53 - 10.1.57
Fixed in 10.1.59
11.0.20 - 11.0.24
Fixed in 11.0.25
Are you affected? Scan for Free

TL;DR

tomcat-embed-core does not fully enforce strict SNI checks for HTTP/2 requests that omit an authority. A client can send a no-authority HTTP/2 request and skip the intended host match. That can route the request to the wrong virtual host. The fix requires every HTTP/2 request to provide an authority.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and HTTP/2 is enabled with strict SNI validation.

Background info

tomcat-embed-core is vulnerable to Improper Input Validation in versions 9.0.115 - 9.0.120, 10.1.53 - 10.1.57 and 11.0.20 - 11.0.24.

How to fix this

Upgrade the org.apache.tomcat.embed:tomcat-embed-core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform