CVE-2026-24733Disclosure(apache / tomcat)

LOWCVSS 3.7 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache tomcat systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tomcat

Threat summary

  • Patch or workaround signal is available
  • 23 mentions across 13 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 9 signals
  • Disclosure: 9 classified signals
  • General: 9 classified signals
  • Peaked 10d ago at 6 mentions (2026-02-19); latest day: 1
  • 23 total mentions across 13 days

Affected systems

Vendors
Products
tomcat

3 versions affected across 1 product

Deep dive

Activity timeline23 mentions / 13d
02356Mentions · 2026-02-17: 1Mentions · 2026-02-18: 3Mentions · 2026-02-19: 6Mentions · 2026-02-20: 1Mentions · 2026-02-21: 1Mentions · 2026-02-22: 1Mentions · 2026-02-23: 1Mentions · 2026-02-27: 1Mentions · 2026-03-09: 3Mentions · 2026-03-12: 1Mentions · 2026-03-23: 2Mentions · 2026-04-16: 1Mentions · 2026-04-21: 1Patch / Workaround · 2026-02-19: 1Patch / Workaround · 2026-02-20: 1Patch / Workaround · 2026-02-22: 1Patch / Workaround · 2026-03-09: 2Patch / Workaround · 2026-03-12: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-20: 1Technical Details · 2026-02-21: 1Technical Details · 2026-02-22: 1Technical Details · 2026-02-27: 1Technical Details · 2026-03-12: 1Technical Details · 2026-03-23: 202-1702-1802-1902-2002-2102-2202-2302-2703-0903-1203-2304-1604-21
Signal classification3 categories
Disclosure
939.1%
General
939.1%
Patch
521.7%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-02-171
Disclosure1
2026-02-183
Disclosure1General2
2026-02-196
Disclosure1General4Patch1
2026-02-201
Disclosure1
2026-02-211
Disclosure1
2026-02-221
Patch1
2026-02-231
Disclosure1
2026-02-271
Disclosure1
2026-03-093
General1Patch2
2026-03-121
Patch1
2026-03-232
Disclosure2
2026-04-161
General1
2026-04-211
General1
Full discourse20 posts
  • Cyber Security News@The_Cyber_News
    Disclosure

    ⚠️ Apache Tomcat Flaw Let Attackers Bypass Security Constraints via HTTP/0.9 Requests Source: https://cybersecuritynews.com/apache-tomcat-bypass-vulnerabilities/ Apache Tomcat has disclosed CVE-2026-24733, a Low-severity security constraint bypass that can be triggered via HTTP/0.9 requests when certain access-control rules are configured in a specific way. However, if an attacker can reach a Tomcat instance and send crafted HTTP/0.9-style traffic, Tomcat’s method handling can create an unexpected gap in enforcement for security constraints. The bypass occurs when a Tomcat security constraint is configured to allow HEAD requests to a given URI while denying GET requests to that same URI. Under normal HTTP versions, that rule set would prevent the retrieval of the resource body via GET. #cybersecuritynews #Apache #Tomcat

    Post summary

    Apache Tomcat disclosed CVE-2026-24733, a low‑severity security constraint bypass triggered by HTTP/0.9 requests, detailing the misconfiguration that allows HEAD requests while denying GET requests.

    6390103264.5K
    46.8K followersView on X
  • cPanel@cPanel
    General

    EasyApache 4 v25.48: • mod_qos → 11.78 • ionCube 15 added (beta for PHP 8.5) • ea-cpanel-tools manifest updated to include ioncube15 • Tomcat 10.1 changelog updated with CVE refs (CVE-2026-24733, CVE-2026-24734, CVE-2025-66614) Full change log: https://docs.cpanel.net/changelogs/easyapache-4-change-log-25/ https://t.co/a0lNz1sFp0

    Post summary

    The update notes that EasyApache 4 v25.48 includes references to three CVEs but provides no additional details, PoC, or exploit information.

    00130405
    28.7K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Apache Tomcat 脆弱性 CVE-2026-24733 が FIX:HTTP/0.9 を介したセキュリティ・バイパス https://iototsecnews.jp/2026/02/20/apache-tomcat-vulnerabilities-let-attackers-bypass-security-constraints-via-http-0-9-requests/ あまりにも古いため、現代ではほぼ使われていないはずの HTTP/0.9 プロトコルを、Apache Tomcat において悪用することで、アクセス制限のバイパスを許す脆弱性 CVE-2026-24733 が発見されました。この問題の根本原因は、Tomcat が HTTP/0.9 リクエストを処理する際に、GET や HEAD などのメソッド制限を、適切に適用できないところにあります。きわめてシンプルな HTTP/0.9 は古い規格であり、GET メソッドしか存在しません。しかし、攻撃者が HTTP/0.9 形式を装いながら、本来は禁止されているはずの場所へアクセスを試みると、Tomcat 側の特定のアクセス制御コンフィグ (例:HEAD は通すが GET は拒否) が混乱し、その結果として、拒否されているはずのデータ (GET リソース) を取得できてしまうという問題が生じます。レガシー環境の確認が必要です。 #Apache #CVE202624733 #Tomcat #Vulnerability

    Post summary

    CVE-2026-24733 exposes a method‑restriction flaw in Apache Tomcat that lets attackers bypass access controls via legacy HTTP/0.9 requests.

    02001166
    485 followersView on X
  • Tomitribe@tomitribe
    General

    CVE-2026-24733 is an #ApacheTomcat vulnerability tied to HTTP/0.9, but its impact isn’t always clear. We’re live tomorrow. Don’t miss it. Join Jon, Cesar, and David as they break down risk and exposure. 📅 Apr 22 at 10AM PT https://bit.ly/3Qep1KC https://t.co/PcCeuWrJJf

    Post summary

    The tweet announces a session to discuss CVE-2026-24733 but does not provide any evidence of exploitation, patches, or technical details.

    00110182
    3.1K followersView on X
  • Tomitribe@tomitribe
    General

    CVE-2026-24733 is an #ApacheTomcat vulnerability tied to HTTP/0.9, but its impact isn’t always clear. Join our team live to break down risk and exposure. Also covering: - CVE-2026-24734 - CVE-2025-66614 📅 Apr 22 at 10AM PT Save your spot: https://bit.ly/3Qep1KC https://t.co/iNsXqpP9JA

    Post summary

    The tweet announces a live event covering three CVEs but offers no technical details, exploits, or mitigation information.

    00011396
    3.1K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    🚨 ثغرات Apache Tomcat تسمح بتجاوز القيود الأمنية تم اكتشاف ثغرات في Apache Tomcat، تحديداً CVE-2026-24733، تسمح للمهاجمين بتجاوز قيود الوصول عند استخدام طلبات HTTP/0.9. هذه الثغرات، رغم تصنيفها منخفضة الخطورة، يمكن استغلالها للوصول غير المصرح به للنظام. 💡 خطوات الحماية: * تأكد من تحديث Apache Tomcat إلى أحدث إصدار متوفر. * قم بمراجعة وتأمين إعدادات الوصول والقيود الأمنية لديك. * راقب سجلات النظام بحثًا عن أي نشاط مشبوه مرتبط بطلبات HTTP. 🔗 https://cybersecuritynews.com/apache-tomcat-bypass-vulnerabilities/ #الأمن_السيبراني #ApacheTomcat #CVE #Vulnerability

    Post summary

    Apache Tomcat CVE-2026-24733 permits access bypass via HTTP/0.9 requests; updating to the latest version and tightening access controls mitigates the risk.

    0002040
    52 followersView on X
  • 豊月@yutuki_r
    General

    Apache Tomcatにおける複数の脆弱性(CVE-2025-66614、CVE-2026-24733、CVE-2026-24734) https://jvn.jp/vu/JVNVU91658988/ #security #feedly

    Post summary

    The tweet lists several CVE identifiers for Apache Tomcat and links to a JVN article, but provides no further details or actionable information.

    1100087
    1.0K followersView on X
  • transilienceai@transilienceai
    Patch

    @yutuki_r @okomeki - **For CVE-2025-66614 and CVE-2026-24733**: Apache Tomcat 11.0.15, 10.1.50, or 9.0.113. #UpdateNow

    Post summary

    The tweet is a patch advisory urging users to update Tomcat to specific versions to mitigate CVE-2025-66614 and CVE-2026-24733.

    1000042
    311 followersView on X
  • transilienceai@transilienceai
    General

    @yutuki_r @okomeki - **CVE-2025-66614 and CVE-2026-24733**: Apache Tomcat 11.0.0-M1 to 11.0.14, 10.1.0-M1 to 10.1.49, 9.0.0.M1 to 9.0.112. #Vulnerabilities

    Post summary

    The tweet announces two CVEs impacting specific Apache Tomcat release ranges, but provides no further technical detail, exploitation status, or mitigation information.

    1000043
    311 followersView on X
  • transilienceai@transilienceai
    Disclosure

    @yutuki_r @okomeki 🚨 Apache Tomcat has multiple recently disclosed vulnerabilities: **CVE-2025-66614** (client certificate authentication bypass), **CVE-2026-24733** (security constraint bypass for GET requests), and **CVE-2026-24734** (certificate revocation check bypass). #ApacheTomcat #Security

    Post summary

    Apache Tomcat has recently disclosed three new vulnerabilities, including authentication, constraint, and revocation check bypasses.

    1000045
    311 followersView on X
  • Kazuki Omo@omokazuki
    General

    Apache Tomcatの脆弱性(Moderate: CVE-2026-24734, Low: CVE-2026-24733) #sios_tech #security #vulnerability #セキュリティ #脆弱性 #linux #tomcat #mod_jk #apache https://security.sios.jp/vulnerability/tomcat-security-vulnerability-20260219/

    Post summary

    The post simply lists two CVEs for Apache Tomcat with their severity levels, without providing details on exploitation, patches, or technical specifics.

    00010115
    360 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-24733 HTTP/0.9 Request Method Bypass Vulnerability in Apache Tomcat https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24733

    Post summary

    The text announces a newly disclosed vulnerability (CVE‑2026‑24733) involving an HTTP/0.9 request method bypass in Apache Tomcat. No PoC, exploit code, or mitigation details are provided.

    0001044
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-24733 Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allo… https://www.cve.org/CVERecord?id=CVE-2026-24733 ----- Traducción: CVE-2026-24733 Vuln… http://infoflow.cloud`

    Post summary

    The tweet announces the discovery of CVE-2026-24733, an Improper Input Validation flaw in Apache Tomcat that allows unrestricted HTTP/0.9 requests.

    0000043
    61 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24733 Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allo… https://www.cve.org/CVERecord?id=CVE-2026-24733

    Post summary

    The text announces CVE-2026-24733 in Apache Tomcat, describing an improper input validation flaw that permits HTTP/0.9 requests to bypass GET constraints – no exploitation, patch, or PoC is disclosed.

    00000217
    56.8K followersView on X
  • ThreatCluster@threatcluster
    Patch

    SUSE releases critical Tomcat 11.0.18 security update for SLES and openSUSE, fixing CVE-2025-66614, CVE-2026-24733 and CVE-2026-24734 affecting TLS cert checks and HTTP/0.9 handling. #Vulnerability https://threatcluster.io/cluster/suse-releases-critical-security-patch-for-tomcat-11-addressi-28d66904

    Post summary

    SUSE released a critical security patch for Tomcat 11.0.18 that fixes three CVEs affecting TLS certificate checks and HTTP/0.9 handling. No active exploitation or PoC is mentioned.

    00000149
    100 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    🚨 #openSUSE Tumbleweed ships Tomcat 9.0.115-1.1, addressing 3 CVEs (CVE-2025-66614, CVE-2026-24733, CVE-2026-24734). Read more: 👉 https://tinyurl.com/2rb5a6t3 #Security https://t.co/aJhl7pQJr3

    Post summary

    The tweet announces that openSUSE Tumbleweed has released Tomcat 9.0.115-1.1, which fixes CVE‑2025‑66614, CVE‑2026‑24733, and CVE‑2026‑24734.

    0000063
    1.3K followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Critical #Tomcat 11 update for openSUSE Tumbleweed. Version 11.0.18-1.1 fixes CVE-2025-66614, CVE-2026-24733, and CVE-2026-24734. Read more: 👉 https://tinyurl.com/pzdjwutx #openSUSE https://t.co/HxBRM65MmY

    Post summary

    The update to Tomcat 11 (version 11.0.18-1.1) for openSUSE Tumbleweed includes critical fixes for CVE‑2025‑66614, CVE‑2026‑24733, and CVE‑2026‑24734.

    0000065
    1.3K followersView on X
  • Sergio Lopes@sergiolopessp
    Disclosure

    No dia 17 de fevereiro de 2026, a equipe de segurança do Apache Tomcat revelou a CVE-2026-24733. Embora classificada como de baixa severidade, ela expõe um comportamento sobre como servidores modernos lidam com protocolos “fósseis”. Entenda: https://deviniciative.wordpress.com/2026/02/23/alem-do-get-e-head-entendendo-o-bypass-de-seguranca-no-apache-tomcat-cve-2026-24733/

    Post summary

    Apache Tomcat announced CVE-2026-24733 as a low‑severity issue affecting how modern servers handle fossil protocols, with a link to a blog post for further details.

    0000069
    1.0K followersView on X
  • ThreatSynop@ThreatSynop
    Disclosure

    🚨 Apache Tomcat HTTP/0.9 Quirk Enables Security-Constraint Bypass (CVE-2026-24733) via Crafted HEAD Requests Apache Tomcat fixed CVE-2026-24733, where HTTP/0.9 handling can let attackers bypass security constraints if a rule set allows HEAD but denies GET on the same URI—by sending an invalid HTTP/0.9 HEAD request that slips past the intended enforcement. Upgrade to Tomcat 11.0.15+, 10.1.50+, or 9.0.113+ and review/prohibit legacy HTTP/0.9 paths at proxies/load balancers to prevent protocol-downgrade edge cases. 🎯 Target: Global/Organizations Running Apache Tomcat #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/apache-tomcat-bypass-vulnerabilities/

    Post summary

    Apache Tomcat announced CVE‑2026‑24733, a security‑constraint bypass via crafted HTTP/0.9 HEAD requests, and advised upgrading to patched versions.

    0000036
    174 followersView on X
  • kawn@kawn2020
    General

    2026. 2.18 JVNVU#91658988 Apache Tomcatにおける複数の脆弱性(CVE-2025-66614、CVE-2026-24733、CVE-2026-24734) - Japan Vulnerability Notes(JVN) https://jvn.jp/vu/JVNVU91658988/

    Post summary

    The entry references a JVN notice listing several Apache Tomcat CVEs but offers no further details on exploitation, patches, or technical aspects.

    0000060
    89 followersView on X
CPE platform detail64 entries

64 of 64 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat---
Appapachetomcat10.0.0--
Appapachetomcat10.0.0--
Appapachetomcat10.0.0--
Appapachetomcat10.0.0--
Appapachetomcat10.0.0--
Appapachetomcat10.0.0--
Appapachetomcat10.0.0--
Appapachetomcat10.0.0--
Appapachetomcat10.0.0--
Appapachetomcat10.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat11.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--
Appapachetomcat9.0.0--

Explore more