CVE-2026-65637
published 2026-08-25CVE-2026-65637: Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through…
PriorityP261critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.75%
52.6th percentile
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990.
This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | tomcat | — | — |
| apache | tomcat | >= 10.1.53 < 10.1.58 | 10.1.58 |
| apache | tomcat | >= 11.0.20 < 11.0.25 | 11.0.25 |
| apache | tomcat | >= 9.0.115 < 9.0.121 | 9.0.121 |
| debian | tomcat10 | — | — |
| debian | tomcat11 | — | — |
| debian | tomcat9 | — | — |
| pki-deps_10.6 | pki-servlet-engine | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_redhat5.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Apache Tomcat: Apache Tomcat: Improper Input Validation allows HTTP/2 no-authority bypass of strict SNI validation
vendor_redhat·2026-08-25·CVSS 5.3
CVE-2026-65637 [MEDIUM] CWE-444 Apache Tomcat: Apache Tomcat: Improper Input Validation allows HTTP/2 no-authority bypass of strict SNI validation
Apache Tomcat: Apache Tomcat: Improper Input Validation allows HTTP/2 no-authority bypass of strict SNI validation
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990.
This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
A flaw was found in Apache Tomcat. This improper input validation vulnerability, stemming from an incomplete fix for CVE-2026-32990, allows for an HTTP/2 no-authority bypass of strict Server Name Indication (SNI) validation. This could potentially lead to unauthorized access or misrouting of requests.
Statement: This Moderate flaw in Apache Tomcat allows an HTTP/
GHSA
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990.
ghsa_unreviewed·2026-08-26·CVSS 5.3
CVE-2026-65637 [MEDIUM] CWE-20 Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990.
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990.
This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-65637 Apache Tomcat: Apache Tomcat: Improper Input Validation allows HTTP/2 no-authority bypass of strict SNI validation
bugzilla·2026-08-25·CVSS 5.3
CVE-2026-65637 [MEDIUM] CVE-2026-65637 Apache Tomcat: Apache Tomcat: Improper Input Validation allows HTTP/2 no-authority bypass of strict SNI validation
CVE-2026-65637 Apache Tomcat: Apache Tomcat: Improper Input Validation allows HTTP/2 no-authority bypass of strict SNI validation
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990.
This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
Bugzilla
CVE-2026-53286 kernel: idpf: fix double free and use-after-free in aux device error paths
bugzilla·2026-06-26
CVE-2026-53286 [MEDIUM] CVE-2026-53286 kernel: idpf: fix double free and use-after-free in aux device error paths
CVE-2026-53286 kernel: idpf: fix double free and use-after-free in aux device error paths
In the Linux kernel, the following vulnerability has been resolved:
idpf: fix double free and use-after-free in aux device error paths
When auxiliary_device_add() fails in idpf_plug_vport_aux_dev() or
idpf_plug_core_aux_dev(), the err_aux_dev_add label calls
auxiliary_device_uninit() and falls through to err_aux_dev_init. The
uninit call will trigger put_device(), which invokes the release
callback (idpf_vport_adev_release / idpf_core_adev_release) that frees
iadev. The fall-through then reads adev->id from the freed iadev for
ida_free() and double-frees iadev with kfree().
Free the IDA slot and clear the back-pointer before uninit, while adev
is still valid, then return immediately.
Commit 65637
Bugzilla
CVE-2025-65637 google-osconfig-agent: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-43]
bugzilla·2025-12-15·CVSS 7.5
CVE-2025-65637 [HIGH] CVE-2025-65637 google-osconfig-agent: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-43]
CVE-2025-65637 google-osconfig-agent: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-43]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
FEDORA-2026-4a2d23b470 (google-osconfig-agent-20260717.00-1.fc43) has been submitted as an update to Fedora 43.
https://bodhi.fedoraproject.org/updates/FEDORA
Bugzilla
CVE-2025-65637 cadvisor: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
bugzilla·2025-12-15·CVSS 7.5
CVE-2025-65637 [HIGH] CVE-2025-65637 cadvisor: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
CVE-2025-65637 cadvisor: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedor
Bugzilla
CVE-2025-65637 manifest-tool: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
bugzilla·2025-12-15·CVSS 7.5
CVE-2025-65637 [HIGH] CVE-2025-65637 manifest-tool: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
CVE-2025-65637 manifest-tool: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is
Bugzilla
CVE-2025-65637 stargz-snapshotter: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
bugzilla·2025-12-15·CVSS 7.5
CVE-2025-65637 [HIGH] CVE-2025-65637 stargz-snapshotter: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
CVE-2025-65637 stargz-snapshotter: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
I
Bugzilla
CVE-2025-65637 golang-x-exp: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
bugzilla·2025-12-15·CVSS 7.5
CVE-2025-65637 [HIGH] CVE-2025-65637 golang-x-exp: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
CVE-2025-65637 golang-x-exp: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is F
Bugzilla
CVE-2025-65637 pack: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [epel-8]
bugzilla·2025-12-15·CVSS 7.5
CVE-2025-65637 [HIGH] CVE-2025-65637 pack: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [epel-8]
CVE-2025-65637 pack: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [epel-8]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
FEDORA-EPEL-2026-8513c30973 (pack-0.40.8-1.el8) has been submitted as an update to Fedora EPEL 8.
https://bodhi.fedoraproject.org/updates/FEDORA-EPEL-2026-8513c30973
---
FEDORA
Bugzilla
CVE-2025-65637 golang-github-facebook-time: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
bugzilla·2025-12-15·CVSS 7.5
CVE-2025-65637 [HIGH] CVE-2025-65637 golang-github-facebook-time: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
CVE-2025-65637 golang-github-facebook-time: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026
Bugzilla
CVE-2025-65637 yubihsm-connector: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
bugzilla·2025-12-15·CVSS 7.5
CVE-2025-65637 [HIGH] CVE-2025-65637 yubihsm-connector: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
CVE-2025-65637 yubihsm-connector: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It
Bugzilla
CVE-2025-65637 trustee-guest-components: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
bugzilla·2025-12-15·CVSS 7.5
CVE-2025-65637 [HIGH] CVE-2025-65637 trustee-guest-components: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
CVE-2025-65637 trustee-guest-components: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05
Bugzilla
CVE-2025-65637 matterbridge: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
bugzilla·2025-12-15·CVSS 7.5
CVE-2025-65637 [HIGH] CVE-2025-65637 matterbridge: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
CVE-2025-65637 matterbridge: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is F
Bugzilla
CVE-2025-65637 kata-containers: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
bugzilla·2025-12-15·CVSS 7.5
CVE-2025-65637 [HIGH] CVE-2025-65637 kata-containers: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
CVE-2025-65637 kata-containers: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It i
Bugzilla
CVE-2025-65637 golang-github-moby-buildkit: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
bugzilla·2025-12-15·CVSS 7.5
CVE-2025-65637 [HIGH] CVE-2025-65637 golang-github-moby-buildkit: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
CVE-2025-65637 golang-github-moby-buildkit: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026
Bugzilla
CVE-2025-65637 kubernetes1.30: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
bugzilla·2025-12-15·CVSS 7.5
CVE-2025-65637 [HIGH] CVE-2025-65637 kubernetes1.30: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
CVE-2025-65637 kubernetes1.30: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is
Bugzilla
CVE-2025-65637 OliveTin: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
bugzilla·2025-12-15·CVSS 7.5
CVE-2025-65637 [HIGH] CVE-2025-65637 OliveTin: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
CVE-2025-65637 OliveTin: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedor
Bugzilla
CVE-2025-65637 kubernetes1.29: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
bugzilla·2025-12-15·CVSS 7.5
CVE-2025-65637 [HIGH] CVE-2025-65637 kubernetes1.29: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
CVE-2025-65637 kubernetes1.29: github.com/sirupsen/logrus: Denial-of-Service due to large single-line payload [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
The following link provides references to all essential vulnerability management information. If something is wrong or missing, please contact a member of PSIRT.
https://spaces.redhat.com/display/PRODSEC/Vulnerability+Management+-+Essential+Documents+for+Engineering+Teams
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is
2026-08-25
Published