cbcvebase.
CVE-2025-66614
published 2026-04-09

CVE-2025-66614: Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through…

PriorityP264critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.24%
14.4th percentile
Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

Affected

16 ranges
VendorProductVersion rangeFixed in
apachetomcat
apachetomcat
apachetomcat
apachetomcat
apachetomcat>= 10.1.1 < 10.1.5010.1.50
apachetomcat>= 10.1.50 < 10.1.5310.1.53
apachetomcat>= 11.0.1 < 11.0.1511.0.15
apachetomcat>= 11.0.15 < 11.0.2011.0.20
apachetomcat>= 9.0.1 < 9.0.1139.0.113
apachetomcat>= 9.0.113 < 9.0.1169.0.116
apache_software_foundationapache_tomcat10.1.50 – 10.1.52
apache_software_foundationapache_tomcat11.0.15 – 11.0.19
apache_software_foundationapache_tomcat9.0.113 – 9.0.115
debiantomcat10< tomcat10 10.1.52-1~deb12u1 (bookworm)tomcat10 10.1.52-1~deb12u1 (bookworm)
debiantomcat11< tomcat10 10.1.52-1~deb12u1 (bookworm)tomcat10 10.1.52-1~deb12u1 (bookworm)
debiantomcat9< tomcat10 10.1.52-1~deb12u1 (bookworm)tomcat10 10.1.52-1~deb12u1 (bookworm)

Detection & IOCsextracted from sources · hover to see the quote

  • Detect mismatch between SNI extension hostname and HTTP Host header field in TLS connections to Apache Tomcat — this is the core exploit primitive for CVE-2025-66614
  • Alert on Apache Tomcat instances with multiple virtual hosts where at least one virtual host enforces client certificate authentication at the Connector level (not at the web application level) — these are the only configurations exploitable
  • For CVE-2026-32990 (incomplete fix follow-on): also detect SNI/Host header mismatches that differ only in case, as the bypass was extended to case-insensitive hostname differences
  • ·Vulnerability only applies when Tomcat is configured with more than one virtual host AND client certificate authentication is enforced at the Connector level on at least one virtual host but not all
  • ·Vulnerability does NOT apply if client certificate authentication is enforced at the web application layer rather than the Connector
  • ·Affected Apache Tomcat version ranges: 11.0.0-M1 through 11.0.14, 10.1.0-M1 through 10.1.49, 9.0.0-M1 through 9.0.112, and EOL 8.5.0 through 8.5.100
  • ·CVE-2026-32990 is a follow-on incomplete-fix CVE affecting Tomcat 11.0.15–11.0.19, 10.1.50–10.1.52, and 9.0.113–9.0.115; the bypass was extended to case-difference SNI/Host mismatches

CVSS provenance

nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
ghsa9.1CRITICAL
osv9.1CRITICAL
vendor_apache9.1
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.