CVE-2026-24880Disclosure(apache / tomcat)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch apache tomcat systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other, unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tomcat

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-04-09); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
tomcat

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-04-09: 1Mentions · 2026-04-12: 1Mentions · 2026-04-13: 1Patch / Workaround · 2026-04-12: 1Patch / Workaround · 2026-04-13: 1Technical Details · 2026-04-09: 1Technical Details · 2026-04-12: 1Technical Details · 2026-04-13: 104-0904-1204-13
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-04-091
Disclosure1
2026-04-121
Patch1
2026-04-131
Disclosure1
Full discourse3 posts
  • Ferramentas Linux@Cezar_H_Linux
    Patch

    Tomcat request smuggling (CVE-2026-24880) isn't going away. Check if you're vulnerable on Ubuntu, Rocky, or SUSE: dpkg -l | grep tomcat9 rpm -qa | grep tomcat zypper info tomcat Then run the fix script → Read more: 👉 https://tinyurl.com/43ud2kjt #Mageia https://t.co/FqhySyZXYS

    Post summary

    The post details a fix for CVE‑2026‑24880, providing commands to verify affected Tomcat versions and a link to a script for remediation.

    0001099
    1.5K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-24880 Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apach… https://www.cve.org/CVERecord?id=CVE-2026-24880

    Post summary

    The text announces CVE-2026-24880, indicating an HTTP smuggling flaw in Apache Tomcat due to invalid chunk extensions, without providing PoC, exploit code, patch info, or evidence of active exploitation.

    00010123
    57.0K followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    `Apache Tomcat` has an HTTP Request/Response Smuggling vulnerability (CVE-2026-24880). This could lead to cache poisoning or security bypass. Monitor official advisories for patches. #ApacheTomcat #Infosec #Vulnerability https://www.pulsepatch.io/posts/cve-2026-24880-apache-tomcat-http-request-smuggling

    Post summary

    The post announces CVE‑2026‑24880 as an HTTP Request/Response Smuggling flaw in Apache Tomcat and urges readers to watch for vendor patches.

    0000056
    13 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appapachetomcat---

Explore more