CVE-2026-24733
published 2026-02-17CVE-2026-24733: Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to…
PriorityP420low3.7CVSS 3.1
AVNACHPRNUINSUCNILAN
EPSS
0.49%
39.5th percentile
Improper Input Validation vulnerability in Apache Tomcat.
Tomcat did not limit HTTP/0.9 requests to the GET method. If a security
constraint was configured to allow HEAD requests to a URI but deny GET
requests, the user could bypass that constraint on GET requests by
sending a (specification invalid) HEAD request using HTTP/0.9.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112.
Older, EOL versions are also affected.
Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.1 < 10.1.50 | 10.1.50 |
| apache | tomcat | >= 11.0.1 < 11.0.15 | 11.0.15 |
| apache | tomcat | >= 9.0.1 < 9.0.113 | 9.0.113 |
| apache_software_foundation | apache_tomcat | <= 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.49 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.14 | — |
| apache_software_foundation | apache_tomcat | 9.0.0.M1 – 9.0.112 | — |
| debian | tomcat10 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
| debian | tomcat11 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
| debian | tomcat9 | < tomcat10 10.1.52-1~deb12u1 (bookworm) | tomcat10 10.1.52-1~deb12u1 (bookworm) |
CVSS provenance
nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
osv3.7LOW
vendor_debian3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Apache Tomcat - Security constraint bypass with HTTP/0.9
ghsa·2026-02-17
CVE-2026-24733 [LOW] CWE-20 Apache Tomcat - Security constraint bypass with HTTP/0.9
Apache Tomcat - Security constraint bypass with HTTP/0.9
Improper Input Validation vulnerability in Apache Tomcat.
Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112.
Older, EOL versions are also affected.
Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.
OSV
CVE-2026-24733: Improper Input Validation vulnerability in Apache Tomcat
osv·2026-02-17·CVSS 3.7
CVE-2026-24733 [LOW] CVE-2026-24733: Improper Input Validation vulnerability in Apache Tomcat
Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.
OSV
Apache Tomcat - Security constraint bypass with HTTP/0.9
osv·2026-02-17
CVE-2026-24733 [LOW] Apache Tomcat - Security constraint bypass with HTTP/0.9
Apache Tomcat - Security constraint bypass with HTTP/0.9
Improper Input Validation vulnerability in Apache Tomcat.
Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112.
Older, EOL versions are also affected.
Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.
Red Hat
tomcat: security constraint bypass with HTTP/0.9
vendor_redhat·2026-02-17·CVSS 3.7
CVE-2026-24733 [LOW] CWE-20 tomcat: security constraint bypass with HTTP/0.9
tomcat: security constraint bypass with HTTP/0.9
Improper Input Validation vulnerability in Apache Tomcat.
Tomcat did not limit HTTP/0.9 requests to the GET method. If a security
constraint was configured to allow HEAD requests to a URI but deny GET
requests, the user could bypass that constraint on GET requests by
sending a (specification invalid) HEAD request using HTTP/0.9.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112.
Older, EOL versions are also affected.
Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.
A flaw was found in Tomcat. An improper input validation vulnerability allows an attacker to bypass security constraints. Speci
Debian
CVE-2026-24733: tomcat10 - Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit...
vendor_debian·2026·CVSS 3.7
CVE-2026-24733 [LOW] CVE-2026-24733: tomcat10 - Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit...
Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.
Scope: local
bookworm: resolved (fixed in 10.1.52-1~deb12u1)
forky: resolved (fixed in 10.1.52-1)
sid: resolved (fixed in 10.1.52-1)
trixie: resolved (fixed in 10.1.52-1~deb13u1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-24733 tomcat: security constraint bypass with HTTP/0.9 [fedora-all]
bugzilla·2026-02-18·CVSS 3.7
CVE-2026-24733 [LOW] CVE-2026-24733 tomcat: security constraint bypass with HTTP/0.9 [fedora-all]
CVE-2026-24733 tomcat: security constraint bypass with HTTP/0.9 [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-24733 tomcat: security constraint bypass with HTTP/0.9
bugzilla·2026-02-17·CVSS 3.7
CVE-2026-24733 [LOW] CVE-2026-24733 tomcat: security constraint bypass with HTTP/0.9
CVE-2026-24733 tomcat: security constraint bypass with HTTP/0.9
Improper Input Validation vulnerability in Apache Tomcat.
Tomcat did not limit HTTP/0.9 requests to the GET method. If a security
constraint was configured to allow HEAD requests to a URI but deny GET
requests, the user could bypass that constraint on GET requests by
sending a (specification invalid) HEAD request using HTTP/0.9.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112.
Older, EOL versions are also affected.
Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.
Wiz
CVE-2026-24733 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.7
CVE-2026-24733 [LOW] CVE-2026-24733 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-24733 :
Java vulnerability analysis and mitigation
Improper Input Validation vulnerability in Apache Tomcat.
Tomcat did not limit HTTP/0.9 requests to the GET method. If a security
constraint was configured to allow HEAD requests to a URI but deny GET
requests, the user could bypass that constraint on GET requests by
sending a (specification invalid) HEAD request using HTTP/0.9.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112.
Older, EOL versions are also affected.
Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.
Source : NVD
## 3.7
Score
Published February 17, 2026
Severity LOW
CNA Score 6.5
Affected Technologi
2026-02-17
Published