Back

CRITICAL

Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete

Published Aug 25, 2026

Description

Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990.

This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120.

Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.

Affected products

Remediation

Red Hat statement

This Moderate flaw in Apache Tomcat allows an HTTP/2 no-authority bypass of strict Server Name Indication (SNI) validation due to improper input handling. This could lead to requests being misrouted to an unintended virtual host, potentially exposing sensitive information or causing service disruption in specific configurations. The impact is limited as it primarily affects request routing rather than arbitrary code execution.

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Metrics

References (5)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner apache
Published Aug 25, 2026
Updated Aug 26, 2026
Reserved Jul 22, 2026
CISA Vulnrichment
Updated Aug 26, 2026
NVD
Status Analyzed
Modified Aug 27, 2026
Red Hat
Severity Moderate
Public date Aug 25, 2026