Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
2886 articles · 109696 vulns · 38/41 feeds (7d)
← Back to list
—
CVE-2026-24880PATCHED
apache software foundation · apache tomcat

Apache Tomcat: Request smuggling via invalid chunk extension

Description

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other, unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue.

Affected Products

VendorProductVersions
apache software foundationapache tomcat11.0.0-M1, 10.1.0-M1, 9.0.0.M1, 8.5.0, 7.0.0

References

  • https://lists.apache.org/thread/2c682qnlg2tv4o5knlggqbl9yc2gb5sn(vendor-advisory)

Related News (2 articles)

Tier C
oss-security8h ago
CVE-2026-24880: Apache Tomcat: Request smuggling via invalid chunk extension
→ No new info (linked only)
Tier C
VulDB9h ago
CVE-2026-24880 | Apache Tomcat up to 11.0.18 HTTP Request request smuggling
→ No new info (linked only)
CISA KEV❌ No
Actively exploited❌ No
Patch available
https://lists.apache.org/thread/2c682qnlg2tv4o5knlggqbl9yc2gb5sn
CWECWE-444
PublishedApr 9, 2026
Last enriched9h agov2
Trending Score31
Source articles2
Independent2
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-35554
Apache Kafka Clients: Kafka Producer Message Corruption and Misrouting via Buffer Pool Race Condition
Trending: 36
MEDIUMCVE-2026-34500
Apache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Trending: 34
IMPORTANTCVE-2026-29146
Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
Trending: 32
NONECVE-2026-25854
Apache Tomcat: Occasionally open redirect
Trending: 31
NONECVE-2026-29145
Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled
Trending: 31

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 9, 2026
Discovered by ZDM
Apr 9, 2026
Updated: description, severity
Apr 9, 2026
Patch Available
Apr 9, 2026

Version History

v2
Last enriched 9h ago
v2Tier C9h ago

Updated severity to CRITICAL, corrected exploit availability to false, and provided a new description with additional details.

descriptionseverity
via VulDB
v110h ago

Initial creation