Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614.
This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Apr 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-184 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Fri, 10 Apr 2026 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Apache
Apache apache Tomcat |
|
| Vendors & Products |
Apache
Apache apache Tomcat |
Thu, 09 Apr 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue. | |
| Title | Apache Tomcat: Fix for CVE-2025-66614 is incomplete | |
| Weaknesses | CWE-20 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-04-09T19:23:49.618Z
Reserved: 2026-03-17T13:55:48.216Z
Link: CVE-2026-32990
No data.
Status : Received
Published: 2026-04-09T20:16:24.810
Modified: 2026-04-09T20:16:24.810
Link: CVE-2026-32990
OpenCVE Enrichment
Updated: 2026-04-10T09:29:39Z