Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3377 articles · 142302 vulns · 36/41 feeds (7d)
← Back to list
5.3
CVE-2026-32990PATCHED
apache · tomcat

Apache Tomcat: Fix for CVE-2025-66614 is incomplete

Description

Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.

Affected Products

VendorProductVersions
apachetomcatmaven/org.apache.tomcat:tomcat: >= 9.0.113, < 9.0.116, maven/org.apache.tomcat:tomcat: >= 10.1.50, < 10.1.53, maven/org.apache.tomcat.embed:tomcat-embed-core: >= 9.0.113, < 9.0.116, maven/org.apache.tomcat.embed:tomcat-embed-core: >= 10.1.50, < 10.1.53, maven/org.apache.tomcat.embed:tomcat-embed-core: >= 11.0.15, < 11.0.20, maven/org.apache.tomcat:tomcat-coyote: >= 9.0.113, < 9.0.116, maven/org.apache.tomcat:tomcat-coyote: >= 10.1.50, < 10.1.53, maven/org.apache.tomcat:tomcat-coyote: >= 11.0.15, <= 11.0.18, maven/org.apache.tomcat:tomcat: >= 11.0.15, <= 11.0.18

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
apachetomcatcert_advisory90%
mavenorg.apache.tomcat:tomcat-catalinaGHSA85%
mavenorg.apache.tomcat:tomcatGHSA85%
mavenorg.apache.tomcat.embed:tomcat-embed-coreGHSA85%
mavenorg.apache.tomcat:tomcat-coyoteGHSA85%

References

  • https://lists.apache.org/thread/1nl9zqft0ksqlhlkd3j4obyjz1ghoyn7(vendor-advisory)

Related News (5 articles)

Tier B
CERT-FR22h ago
Multiples vulnérabilités dans les produits VMware (11 mai 2026)
→ No new info (linked only)
Tier B
BSI Advisories31d ago
[NEU] [mittel] Apache Tomcat und Tomcat Native: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR31d ago
Multiples vulnérabilités dans Apache Tomcat (10 avril 2026)
→ No new info (linked only)
Tier C
oss-security31d ago
CVE-2026-32990: Apache Tomcat: Fix for CVE-2025-66614 is incomplete
→ No new info (linked only)
Tier C
VulDB32d ago
CVE-2026-32990 | Apache Tomcat up to 9.0.115/10.1.52/11.0.19 input validation
→ No new info (linked only)
CVSS 3.15.3 MEDIUM
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
org.apache.tomcat:tomcat@9.0.116org.apache.tomcat:tomcat@10.1.53org.apache.tomcat.embed:tomcat-embed-core@9.0.116org.apache.tomcat.embed:tomcat-embed-core@10.1.53org.apache.tomcat.embed:tomcat-embed-core@11.0.20org.apache.tomcat:tomcat-coyote@9.0.116org.apache.tomcat:tomcat-coyote@10.1.53org.apache.tomcat:tomcat-coyote@11.0.20org.apache.tomcat:tomcat@11.0.20
CWECWE-20
PublishedApr 9, 2026
Last enriched32d agov2
Trending Score48
Source articles5
Independent4
Info Completeness8/14
Missing: cvss, epss, kev, exploit, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-29129EXP
Apache Tomcat: TLS cipher order is not preserved
Trending: 68
HIGHCVE-2026-23918EXP
Apache HTTP Server: http2: double free and possible RCE on early reset
Trending: 62
HIGHCVE-2026-42499EXP
Quadratic string concatenation in consumePhrase in net/mail
Trending: 58
CRITICALCVE-2026-29145
Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled
Trending: 55
HIGHCVE-2026-24880
Apache Tomcat: Request smuggling via invalid chunk extension
Trending: 52

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Apr 9, 2026
Discovered by ZDM
Apr 9, 2026
Updated: severity
Apr 9, 2026
Patch Available
Apr 10, 2026

Version History

v2
Last enriched 32d ago
v2Tier C32d ago

Updated severity to CRITICAL and noted that no exploit is available.

severity
via VulDB
v132d ago

Initial creation