CVE-2025-66614
published 2026-04-09CVE-2025-66614: Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through…
PriorityP264critical9.1CVSS 3.1
AVNACLPRNUINSUCHIHAN
EPSS
0.24%
14.4th percentile
Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614.
This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.1 < 10.1.50 | 10.1.50 |
| apache | tomcat | >= 10.1.50 < 10.1.53 | 10.1.53 |
| apache | tomcat | >= 11.0.1 < 11.0.15 | 11.0.15 |
| apache | tomcat | >= 11.0.15 < 11.0.20 | 11.0.20 |
| apache | tomcat | >= 9.0.1 < 9.0.113 | 9.0.113 |
| apache | tomcat | >= 9.0.113 < 9.0.116 | 9.0.116 |
| apache_software_foundation | apache_tomcat | 10.1.50 – 10.1.52 | — |
| apache_software_foundation | apache_tomcat | 11.0.15 – 11.0.19 | — |
| apache_software_foundation | apache_tomcat | 9.0.113 – 9.0.115 | — |
| debian | tomcat10 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
| debian | tomcat11 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect mismatch between SNI extension hostname and HTTP Host header field in TLS connections to Apache Tomcat — this is the core exploit primitive for CVE-2025-66614 ↗
- →Alert on Apache Tomcat instances with multiple virtual hosts where at least one virtual host enforces client certificate authentication at the Connector level (not at the web application level) — these are the only configurations exploitable ↗
- →For CVE-2026-32990 (incomplete fix follow-on): also detect SNI/Host header mismatches that differ only in case, as the bypass was extended to case-insensitive hostname differences ↗
- ·Vulnerability only applies when Tomcat is configured with more than one virtual host AND client certificate authentication is enforced at the Connector level on at least one virtual host but not all ↗
- ·Vulnerability does NOT apply if client certificate authentication is enforced at the web application layer rather than the Connector ↗
- ·Affected Apache Tomcat version ranges: 11.0.0-M1 through 11.0.14, 10.1.0-M1 through 10.1.49, 9.0.0-M1 through 9.0.112, and EOL 8.5.0 through 8.5.100 ↗
- ·CVE-2026-32990 is a follow-on incomplete-fix CVE affecting Tomcat 11.0.15–11.0.19, 10.1.50–10.1.52, and 9.0.113–9.0.115; the bypass was extended to case-difference SNI/Host mismatches ↗
CVSS provenance
nvdv3.19.1CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
ghsa9.1CRITICAL
osv9.1CRITICAL
vendor_apache9.1
vendor_debian9.1CRITICAL
vendor_redhat9.1CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Tomcat has an Improper Input Validation vulnerability
ghsa·2026-04-09·CVSS 9.1
CVE-2026-32990 [CRITICAL] CWE-20 Apache Tomcat has an Improper Input Validation vulnerability
Apache Tomcat has an Improper Input Validation vulnerability
Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614.
This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
GHSA
GHSA-8mc5-53m5-3qj2: Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614
ghsa_unreviewed·2026-04-09·CVSS 9.1
CVE-2026-32990 [CRITICAL] CWE-20 GHSA-8mc5-53m5-3qj2: Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614
Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614.
This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
OSV
Apache Tomcat - Client certificate verification bypass
osv·2026-02-17
CVE-2025-66614 [MEDIUM] Apache Tomcat - Client certificate verification bypass
Apache Tomcat - Client certificate verification bypass
Improper Input Validation vulnerability.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112.
The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different
GHSA
Apache Tomcat - Client certificate verification bypass
ghsa·2026-02-17
CVE-2025-66614 [MEDIUM] CWE-20 Apache Tomcat - Client certificate verification bypass
Apache Tomcat - Client certificate verification bypass
Improper Input Validation vulnerability.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112.
The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different
OSV
CVE-2025-66614: Improper Input Validation vulnerability
osv·2026-02-17·CVSS 9.1
CVE-2025-66614 [CRITICAL] CVE-2025-66614: Improper Input Validation vulnerability
Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header
Red Hat
Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix
vendor_redhat·2026-04-09·CVSS 9.1
CVE-2026-32990 [CRITICAL] CWE-184 Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix
Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix
A flaw was found in Apache Tomcat. This improper input validation vulnerability stems from an incomplete fix for a previous security issue (CVE-2025-66614). This flaw may allow an attacker to bypass security controls or cause unexpected behavior within the application.
Statement: Moderate impact. This improper input validation vulnerability in Apache Tomcat, stemming from an incomplete fix for CVE-2025-66614, affects Red Hat JBoss Web Server and Red Hat Enterprise Linux. An attacker could exploit this flaw to bypass security controls or induce unexpected application behavior.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat P
Red Hat
tomcat: Client certificate verification bypass due to virtual host mapping
vendor_redhat·2026-02-17·CVSS 9.1
CVE-2025-66614 [CRITICAL] CWE-1289 tomcat: Client certificate verification bypass due to virtual host mapping
tomcat: Client certificate verification bypass due to virtual host mapping
Improper Input Validation vulnerability.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected.
Tomcat did not validate that the host name provided via the SNI
extension was the same as the host name provided in the HTTP host header
field. If Tomcat was configured with more than one virtual host and the
TLS configuration for one of those hosts did not require client
certificate authentication but another one did, it was possible for a
client to bypass the client certificate authentication by
Debian
CVE-2025-66614: tomcat10 - Improper Input Validation vulnerability. This issue affects Apache Tomcat: from...
vendor_debian·2025·CVSS 9.1
CVE-2025-66614 [CRITICAL] CVE-2025-66614: tomcat10 - Improper Input Validation vulnerability. This issue affects Apache Tomcat: from...
Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header
Apache
Apache tomcat: CVE-2025-66614
vendor_apache·CVSS 9.1
CVE-2025-66614 Apache tomcat: CVE-2025-66614
Apache tomcat: CVE-2025-66614
CVE-2026-32990 The validation of SNI name and host name did not take account of possible differences in case allowing the strict SNI checks to be bypassed. This was fixed with commit 021d1f83 . This issue was reported to the Tomcat security team on 13 March 2026. The issue was made public on 9 April 2026. Affects: 11.0.15 to 11.0.19 Note: The issues below were fixed in Apache Tomcat 11.0.19 but the release vote for the 11.0.19 release candidate did not pass. Therefore, although users must download 11.0.20 to obtain a version that includes a fix for these issues, version 11.0.19 is not included in the list of affected versions.
Severity: moderate
Affected versions: 11.0.19
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-32990 Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix
bugzilla·2026-04-09·CVSS 9.1
CVE-2026-32990 [CRITICAL] CVE-2026-32990 Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix
CVE-2026-32990 Apache Tomcat: Apache Tomcat: Improper Input Validation vulnerability due to incomplete fix
Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614.
This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
Bugzilla
CVE-2025-66614 tomcat: Client certificate verification bypass due to virtual host mapping [fedora-43]
bugzilla·2026-02-18·CVSS 9.1
CVE-2025-66614 [CRITICAL] CVE-2025-66614 tomcat: Client certificate verification bypass due to virtual host mapping [fedora-43]
CVE-2025-66614 tomcat: Client certificate verification bypass due to virtual host mapping [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-66614 tomcat: Client certificate verification bypass due to virtual host mapping [fedora-42]
bugzilla·2026-02-18·CVSS 9.1
CVE-2025-66614 [CRITICAL] CVE-2025-66614 tomcat: Client certificate verification bypass due to virtual host mapping [fedora-42]
CVE-2025-66614 tomcat: Client certificate verification bypass due to virtual host mapping [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2025-66614 tomcat: Client certificate verification bypass due to virtual host mapping
bugzilla·2026-02-17·CVSS 9.1
CVE-2025-66614 [CRITICAL] CVE-2025-66614 tomcat: Client certificate verification bypass due to virtual host mapping
CVE-2025-66614 tomcat: Client certificate verification bypass due to virtual host mapping
Improper Input Validation vulnerability.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected.
Tomcat did not validate that the host name provided via the SNI
extension was the same as the host name provided in the HTTP host header
field. If Tomcat was configured with more than one virtual host and the
TLS configuration for one of those hosts did not require client
certificate authentication but another one did, it was possible for a
client to bypass the client certificate
Wiz
CVE-2025-66614 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 9.1
CVE-2025-66614 [CRITICAL] CVE-2025-66614 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-66614 :
Java vulnerability analysis and mitigation
Improper Input Validation vulnerability.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected.
Tomcat did not validate that the host name provided via the SNI
extension was the same as the host name provided in the HTTP host header
field. If Tomcat was configured with more than one virtual host and the
TLS configuration for one of those hosts did not require client
certificate authentication but another one did, it was possible for a
client to bypass the client certificate authentication by sending
2026-04-09
Published