CVE-2026-32990
Vulnerability Summary
Timeline
Description
Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
CVSS Metrics
- v4.0•MEDIUM•Score: 6.9CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N
- v3.1•MEDIUM•Score: 5.3CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS Trends
Current EPSS score: 0.31%• Percentile: 24%
Techniques & Countermeasures
- CWE-20•Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Affected Systems
- apache software foundation•apache tomcat
≥ 11.0.15, ≤ 11.0.19 | ≥ 10.1.50, ≤ 10.1.52 | ≥ 9.0.113, ≤ 9.0.115
- apache•tomcat
≥ 9.0.113, < 9.0.116 | ≥ 10.1.50, < 10.1.53 | ≥ 11.0.15, < 11.0.20
- debian•tomcat10
< 10.1.55-1~deb12u1 | < 10.1.55-1~deb13u1 | < 10.1.54-1
- debian•tomcat11
< 11.0.22-1~deb13u1 | < 11.0.21-1
- debian•tomcat9
< 9.0.118-0+deb11u1 | < 9.0.70-2 | < 9.0.70-2 | < 9.0.70-2
- org.apache.tomcat•tomcat
≥ 9.0.113, < 9.0.116 | ≥ 10.1.50, < 10.1.53 | ≥ 11.0.15, < 11.0.20
- org.apache.tomcat•tomcat-catalina
≥ 9.0.113, < 9.0.116 | ≥ 10.1.50, < 10.1.53 | ≥ 11.0.15, < 11.0.20
- org.apache.tomcat•tomcat-coyote
≥ 9.0.113, < 9.0.116 | ≥ 10.1.50, < 10.1.53 | ≥ 11.0.15, < 11.0.20
- org.apache.tomcat.embed•tomcat-embed-core
≥ 9.0.113, < 9.0.116 | ≥ 10.1.50, < 10.1.53 | ≥ 11.0.15, < 11.0.20
References (11)
- https://lists.apache.org/thread/1nl9zqft0ksqlhlkd3j4obyjz1ghoyn7
- https://nvd.nist.gov/vuln/detail/CVE-2026-32990
- https://github.com/apache/tomcat
- https://github.com/apache/tomcat/commit/021d1f833e38b683a44688f7b28f1f27e8e37c36
- https://github.com/apache/tomcat/commit/4d0615a5c718c260d6d4e0b944a050f09a490c02
- https://github.com/apache/tomcat/commit/95f7778248cac46d03e6af04de9c72a598be3a53
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.53
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.20
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.116
- https://www.herodevs.com/vulnerability-directory/cve-2026-32990
- https://security-tracker.debian.org/tracker/CVE-2026-32990