Description

Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 10, 2026 · Source: CVE List

Affected products and versions

4
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List11.0.15 to ≤ 11.0.19affected
10.1.50 to ≤ 10.1.52affected
9.0.113 to ≤ 9.0.115affected

org.apache.tomcat.embed:tomcat-embed-core

Browse Maven / org.apache.tomcat.embed:tomcat-embed-core
GitHub Advisory9.0.113 to < 9.0.116 · Fixed in 9.0.116affected
10.1.50 to < 10.1.53 · Fixed in 10.1.53affected
11.0.15 to < 11.0.20 · Fixed in 11.0.20affected
GitHub Advisory9.0.113 to < 9.0.116 · Fixed in 9.0.116affected
10.1.50 to < 10.1.53 · Fixed in 10.1.53affected
11.0.15 to < 11.0.20 · Fixed in 11.0.20affected

org.apache.tomcat:tomcat-coyote

Browse Maven / org.apache.tomcat:tomcat-coyote
GitHub Advisory9.0.113 to < 9.0.116 · Fixed in 9.0.116affected
10.1.50 to < 10.1.53 · Fixed in 10.1.53affected
11.0.15 to < 11.0.20 · Fixed in 11.0.20affected

References

10