CVE-2026-24880
published 2026-04-09CVE-2026-24880: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects…
PriorityP352high7.5CVSS 3.1
AVNACLPRNUINSUCNIHAN
EPSS
0.52%
41.1th percentile
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Other, unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | >= 10.1.0 < 10.1.53 | 10.1.53 |
| apache | tomcat | >= 11.0.0 < 11.0.20 | 11.0.20 |
| apache | tomcat | >= 9.0.0 < 9.0.116 | 9.0.116 |
| apache_software_foundation | apache_tomcat | 10.1.0-M1 – 10.1.52 | — |
| apache_software_foundation | apache_tomcat | 11.0.0-M1 – 11.0.18 | — |
| apache_software_foundation | apache_tomcat | 7.0.0 – 7.0.109 | — |
| apache_software_foundation | apache_tomcat | 8.5.0 – 8.5.100 | — |
| apache_software_foundation | apache_tomcat | 9.0.0.M1 – 9.0.115 | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-563x-q5rq-57qp: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension
ghsa_unreviewed·2026-04-09
CVE-2026-24880 CWE-444 GHSA-563x-q5rq-57qp: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Other, unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue.
GHSA
Apache Tomcat has an HTTP Request/Response Smuggling vulnerability
ghsa·2026-04-09
CVE-2026-24880 [HIGH] CWE-444 Apache Tomcat has an HTTP Request/Response Smuggling vulnerability
Apache Tomcat has an HTTP Request/Response Smuggling vulnerability
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Other, unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue.
VulDB
Apache Tomcat up to 11.0.18 HTTP Request request smuggling
vuldb·2026-04-09·CVSS 7.5
CVE-2026-24880 [HIGH] Apache Tomcat up to 11.0.18 HTTP Request request smuggling
A vulnerability has been found in Apache Tomcat up to 11.0.18 and classified as critical. Affected by this vulnerability is an unknown functionality of the component HTTP Request Handler. This manipulation causes http request smuggling.
This vulnerability appears as CVE-2026-24880. The attack may be initiated remotely. There is no available exploit.
The affected component should be upgraded.
Red Hat
Apache Tomcat: Apache Tomcat: HTTP Request/Response Smuggling via invalid chunk extension
vendor_redhat·2026-04-09·CVSS 7.5
CVE-2026-24880 [HIGH] CWE-444 Apache Tomcat: Apache Tomcat: HTTP Request/Response Smuggling via invalid chunk extension
Apache Tomcat: Apache Tomcat: HTTP Request/Response Smuggling via invalid chunk extension
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Other, unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue.
A flaw was found in Apache Tomcat. A remote attacker could exploit an inconsistent interpretation of HTTP requests, known as HTTP Request/Response Smuggling, by sending a specially crafted request with an invalid chunk extension. This vul
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-24880 tomcat: Apache Tomcat: HTTP Request/Response Smuggling via invalid chunk extension [fedora-all]
bugzilla·2026-04-10·CVSS 7.5
CVE-2026-24880 [HIGH] CVE-2026-24880 tomcat: Apache Tomcat: HTTP Request/Response Smuggling via invalid chunk extension [fedora-all]
CVE-2026-24880 tomcat: Apache Tomcat: HTTP Request/Response Smuggling via invalid chunk extension [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Bugzilla
CVE-2026-24880 Apache Tomcat: Apache Tomcat: HTTP Request/Response Smuggling via invalid chunk extension
bugzilla·2026-04-09·CVSS 7.5
CVE-2026-24880 [HIGH] CVE-2026-24880 Apache Tomcat: Apache Tomcat: HTTP Request/Response Smuggling via invalid chunk extension
CVE-2026-24880 Apache Tomcat: Apache Tomcat: HTTP Request/Response Smuggling via invalid chunk extension
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Other, unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue.
2026-04-09
Published