CVE-2025-66614Disclosure(apache / tomcat)

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache tomcat systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field. The vulnerability only applies if client certificate authentication is only enforced at the Connector. It does not apply if client certificate authentication is enforced at the web application. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fix the issue.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-295

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tomcat

Threat summary

  • Patch or workaround signal is available
  • 19 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 8 signals
  • Disclosure: 8 classified signals
  • General: 5 classified signals
  • Peaked 6d ago at 6 mentions (2026-02-19); latest day: 1
  • 19 total mentions across 9 days

Affected systems

Vendors
Products
tomcat

3 versions affected across 1 product

Deep dive

Activity timeline19 mentions / 9d
02356Mentions · 2026-02-17: 1Mentions · 2026-02-18: 2Mentions · 2026-02-19: 6Mentions · 2026-03-09: 3Mentions · 2026-03-12: 2Mentions · 2026-03-14: 1Mentions · 2026-03-23: 2Mentions · 2026-04-09: 1Mentions · 2026-04-16: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-03-09: 2Patch / Workaround · 2026-03-12: 2Patch / Workaround · 2026-03-14: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-19: 1Technical Details · 2026-03-12: 2Technical Details · 2026-03-14: 1Technical Details · 2026-03-23: 2Technical Details · 2026-04-09: 102-1702-1802-1903-0903-1203-1403-2304-0904-16
Signal classification3 categories
Disclosure
842.1%
Patch
631.6%
General
526.3%
Referenced assets13 URLs
Classification over time
DateTotalLabels
2026-02-171
General1
2026-02-182
Disclosure2
2026-02-196
Disclosure3General2Patch1
2026-03-093
General1Patch2
2026-03-122
Patch2
2026-03-141
Patch1
2026-03-232
Disclosure2
2026-04-091
Disclosure1
2026-04-161
General1
Full discourse19 posts
  • cPanel@cPanel
    General

    EasyApache 4 v25.48: • mod_qos → 11.78 • ionCube 15 added (beta for PHP 8.5) • ea-cpanel-tools manifest updated to include ioncube15 • Tomcat 10.1 changelog updated with CVE refs (CVE-2026-24733, CVE-2026-24734, CVE-2025-66614) Full change log: https://docs.cpanel.net/changelogs/easyapache-4-change-log-25/ https://t.co/a0lNz1sFp0

    Post summary

    The tweet announces an EasyApache 4 release and points to a Tomcat 10.1 changelog with CVE references, providing no additional technical or exploit details.

    00130405
    28.7K followersView on X
  • Tomitribe@tomitribe
    General

    CVE-2026-24733 is an #ApacheTomcat vulnerability tied to HTTP/0.9, but its impact isn’t always clear. Join our team live to break down risk and exposure. Also covering: - CVE-2026-24734 - CVE-2025-66614 📅 Apr 22 at 10AM PT Save your spot: https://bit.ly/3Qep1KC https://t.co/iNsXqpP9JA

    Post summary

    The post is an event announcement that mentions a few CVEs but provides no substantive details, proofs of concept, or evidence of exploitation.

    00011396
    3.1K followersView on X
  • 豊月@yutuki_r
    Disclosure

    Apache Tomcatにおける複数の脆弱性(CVE-2025-66614、CVE-2026-24733、CVE-2026-24734) https://jvn.jp/vu/JVNVU91658988/ #security #feedly

    Post summary

    The tweet announces several new CVEs impacting Apache Tomcat and provides a link to a Japanese vulnerability database, but offers no details on exploitation, patches, or PoCs.

    1100087
    1.0K followersView on X
  • transilienceai@transilienceai
    Patch

    @yutuki_r @okomeki - **For CVE-2025-66614 and CVE-2026-24733**: Apache Tomcat 11.0.15, 10.1.50, or 9.0.113. #UpdateNow

    Post summary

    The tweet urges users to update Apache Tomcat to specific versions to remediate CVE-2025-66614 and CVE-2026-24733, with no PoC or exploitation details provided.

    1000042
    311 followersView on X
  • transilienceai@transilienceai
    General

    @yutuki_r @okomeki - **CVE-2025-66614 and CVE-2026-24733**: Apache Tomcat 11.0.0-M1 to 11.0.14, 10.1.0-M1 to 10.1.49, 9.0.0.M1 to 9.0.112. #Vulnerabilities

    Post summary

    The tweet lists two CVEs affecting various Apache Tomcat releases but provides no details on exploitation, patches, or the nature of the vulnerabilities.

    1000043
    311 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @yutuki_r @okomeki 🚨 Apache Tomcat has multiple recently disclosed vulnerabilities: **CVE-2025-66614** (client certificate authentication bypass), **CVE-2026-24733** (security constraint bypass for GET requests), and **CVE-2026-24734** (certificate revocation check bypass). #ApacheTomcat #Security

    Post summary

    Apache Tomcat vulnerabilities CVE-2025-66614, CVE-2026-24733, and CVE-2026-24734 have been announced with brief technical details, but no PoC, exploit, or patch information is provided.

    1000045
    311 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2025-66614 Apache Tomcat SNI and Host Header Validation Bypass Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2025-66614

    Post summary

    The passage only announces CVE-2025-66614 as a Tomcat SNI and Host Header Validation bypass, without any evidence of PoC, exploit code, active exploitation, or patch information.

    0001042
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-32990 Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, … https://www.cve.org/CVERecord?id=CVE-2026-32990

    Post summary

    This is a disclosure of CVE-2026-32990, an improper input validation flaw in Apache Tomcat affecting versions 11.0.15 through 11.0.19, arising from an incomplete fix of CVE-2025-66614; no exploit, PoC, or patch information is provided.

    00000185
    57.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2025-66614 Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.… https://www.cve.org/CVERecord?id=CVE-2025-66614 ----- Traducción: CVE-2025-66614 Vul… http://infoflow.cloud`

    Post summary

    The message announces CVE-2025-66614, identifying it as an Improper Input Validation issue affecting multiple Apache Tomcat releases, and provides a link to the CVE record.

    0000063
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-66614 Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.… https://www.cve.org/CVERecord?id=CVE-2025-66614

    Post summary

    The text announces CVE-2025-66614 for Apache Tomcat, specifies affected releases, and describes the flaw as an improper input validation vulnerability, without providing PoC, exploitation details, or patch information.

    00000224
    56.8K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    #openSUSE Leap 16.0 admins: IMMEDIATE ACTION REQUIRED. New Tomcat update (9.0.115) patches three high-severity flaws, incl. CVE-2025-66614 (certificate bypass, CVSS 8.7). Read more: 👉 https://tinyurl.com/cnk4a8f8 #Security https://t.co/a5lv0BXYBy

    Post summary

    The tweet warns openSUSE Leap 16.0 administrators that an immediate patch (Tomcat 9.0.115) addresses CVE‑2025‑66614 and two other high‑severity flaws, urging them to apply the update.

    00000209
    1.4K followersView on X
  • ThreatCluster@threatcluster
    Patch

    SUSE releases critical Tomcat 11.0.18 security update for SLES and openSUSE, fixing CVE-2025-66614, CVE-2026-24733 and CVE-2026-24734 affecting TLS cert checks and HTTP/0.9 handling. #Vulnerability https://threatcluster.io/cluster/suse-releases-critical-security-patch-for-tomcat-11-addressi-28d66904

    Post summary

    SUSE announced a critical update for Tomcat 11.0.18 that addresses three CVEs impacting TLS certificate validation and HTTP/0.9 handling, providing patch information without any exploit or PoC details.

    00000149
    100 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical #security update for #Tomcat11 on #SUSE Linux (SUSE-SU-2026:0877-1) patches a CVSS 9.1 client certificate bypass (CVE-2025-66614). Read more: 👉 https://tinyurl.com/3yd9a4zr #Security https://t.co/cWxLI5K9Zw

    Post summary

    A critical security update for Tomcat 11 on SUSE Linux addresses CVE‑2025‑66614, a CVSS 9.1 client‑certificate bypass vulnerability.

    00000135
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 #openSUSE Tumbleweed ships Tomcat 9.0.115-1.1, addressing 3 CVEs (CVE-2025-66614, CVE-2026-24733, CVE-2026-24734). Read more: 👉 https://tinyurl.com/2rb5a6t3 #Security https://t.co/aJhl7pQJr3

    Post summary

    The tweet announces that openSUSE Tumbleweed's Tomcat update to 9.0.115‑1.1 patches CVE‑2025‑66614, CVE‑2026‑24733, and CVE‑2026‑24734, with no exploitation or vulnerability details provided.

    0000063
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical #Tomcat 11 update for openSUSE Tumbleweed. Version 11.0.18-1.1 fixes CVE-2025-66614, CVE-2026-24733, and CVE-2026-24734. Read more: 👉 https://tinyurl.com/pzdjwutx #openSUSE https://t.co/HxBRM65MmY

    Post summary

    A critical Tomcat 11 update for openSUSE Tumbleweed is announced, stating that three CVEs (CVE-2025-66614, CVE-2026-24733, CVE-2026-24734) are fixed in the new version.

    0000065
    1.3K followersView on X
  • kawn@kawn2020
    Disclosure

    2026. 2.18 JVNVU#91658988 Apache Tomcatにおける複数の脆弱性(CVE-2025-66614、CVE-2026-24733、CVE-2026-24734) - Japan Vulnerability Notes(JVN) https://jvn.jp/vu/JVNVU91658988/

    Post summary

    JVN published a notice listing multiple vulnerabilities affecting Apache Tomcat, namely CVE-2025-66614, CVE-2026-24733, and CVE-2026-24734.

    0000060
    89 followersView on X
  • jpsecuritynews@jpsecuritynews
    General

    [JVNVU#91658988] Apache Tomcatにおける複数の脆弱性(CVE-2025-66614、CVE-2026-24733、CVE-2026-24734) https://jvn.jp/vu/JVNVU91658988/ #jvn #脆弱性 #セキュリティ

    Post summary

    The tweet merely announces the existence of multiple Apache Tomcat vulnerabilities (CVE‑2025‑66614, CVE‑2026‑24733, CVE‑2026‑24734) and links to a JVN entry, without providing further technical or exploitation details.

    0000048
    30 followersView on X
  • 珈琲好き@likecoffee
    Disclosure

    Apache Tomcatにおける複数の脆弱性(CVE-2025-66614、CVE-2026-24733、CVE-2026-24734) https://jvn.jp/vu/JVNVU91658988/ #%E6%8A%80%E8%A1%93%E7%B3%BB-%E3%82%BB%E3%82%AD%E3%83%A5%E3%83%AA%E3%83%86%E3%82%A3 #feedly

    Post summary

    The tweet cites several Apache Tomcat CVEs and links to a JVN article, but does not provide PoC, exploit details, or mitigation information.

    0000048
    1.5K followersView on X
  • ITセキュリティ情報@itsec_jp
    Disclosure

    統合版 JPCERT/CC | JVN: Apache Tomcatにおける複数の脆弱性(CVE-2025-66614、CVE-2026-24733、CVE-2026-24734) https://ift.tt/wUAnzvK #itsec_jp

    Post summary

    The tweet links to a JVN post announcing several Apache Tomcat vulnerabilities (CVE-2025-66614, CVE-2026-24733, CVE-2026-24734).

    00000100
    1.2K followersView on X
CPE platform detail74 entries

74 of 74 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat---
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat10.1.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--

Explore more