
⚠️ Apache Tomcat Flaw Let Attackers Bypass Security Constraints via HTTP/0.9 Requests Source: https://cybersecuritynews.com/apache-tomcat-bypass-vulnerabilities/ Apache Tomcat has disclosed CVE-2026-24733, a Low-severity security constraint bypass that can be triggered via HTTP/0.9 requests when certain access-control rules are configured in a specific way. However, if an attacker can reach a Tomcat instance and send crafted HTTP/0.9-style traffic, Tomcat’s method handling can create an unexpected gap in enforcement for security constraints. The bypass occurs when a Tomcat security constraint is configured to allow HEAD requests to a given URI while denying GET requests to that same URI. Under normal HTTP versions, that rule set would prevent the retrieval of the resource body via GET. #cybersecuritynews #Apache #Tomcat
Post summary
Apache Tomcat disclosed CVE-2026-24733, a low‑severity security constraint bypass triggered by HTTP/0.9 requests, detailing the misconfiguration that allows HEAD requests while denying GET requests.















