github.com
https://github.com/apache/tomcat CVE-2026-32990
Apache Tomcat: Fix for CVE-2025-66614 is incomplete
Description
Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 10, 2026 · Source: CVE List
Affected products and versions
4| Product | Source | Version range | Status |
|---|---|---|---|
Apache TomcatBrowse Apache Software Foundation / Apache TomcatDefault status: unaffected | CVE List | 11.0.15 to ≤ 11.0.19 | affected |
| 10.1.50 to ≤ 10.1.52 | affected | ||
| 9.0.113 to ≤ 9.0.115 | affected | ||
org.apache.tomcat.embed:tomcat-embed-coreBrowse Maven / org.apache.tomcat.embed:tomcat-embed-core | GitHub Advisory | 9.0.113 to < 9.0.116 · Fixed in 9.0.116 | affected |
| 10.1.50 to < 10.1.53 · Fixed in 10.1.53 | affected | ||
| 11.0.15 to < 11.0.20 · Fixed in 11.0.20 | affected | ||
org.apache.tomcat:tomcatBrowse Maven / org.apache.tomcat:tomcat | GitHub Advisory | 9.0.113 to < 9.0.116 · Fixed in 9.0.116 | affected |
| 10.1.50 to < 10.1.53 · Fixed in 10.1.53 | affected | ||
| 11.0.15 to < 11.0.20 · Fixed in 11.0.20 | affected | ||
org.apache.tomcat:tomcat-coyoteBrowse Maven / org.apache.tomcat:tomcat-coyote | GitHub Advisory | 9.0.113 to < 9.0.116 · Fixed in 9.0.116 | affected |
| 10.1.50 to < 10.1.53 · Fixed in 10.1.53 | affected | ||
| 11.0.15 to < 11.0.20 · Fixed in 11.0.20 | affected |
References
10github.com
https://github.com/apache/tomcat/commit/021d1f833e38b683a44688f7b28f1f27e8e37c36 github.com
https://github.com/apache/tomcat/commit/4d0615a5c718c260d6d4e0b944a050f09a490c02 github.com
https://github.com/apache/tomcat/commit/95f7778248cac46d03e6af04de9c72a598be3a53 lists.apache.orgVendor advisory
https://lists.apache.org/thread/1nl9zqft0ksqlhlkd3j4obyjz1ghoyn7 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2026-32990 tomcat.apache.org
https://tomcat.apache.org/security-10.html tomcat.apache.org
https://tomcat.apache.org/security-11.html tomcat.apache.org
https://tomcat.apache.org/security-9.html herodevs.com
https://www.herodevs.com/vulnerability-directory/cve-2026-32990