Description
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
CVSS 9.8EPSS 0.754%Risk 1.05
View source- Published
- 2026-08-25 22:17:05
- Affected versions
- >=11.0.20,<11.0.25,>=10.1.53,<10.1.58,>=9.0.115,<9.0.121
- Type
- Web application
- Last modified
- 2026-08-27 15:19:42
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H