Apache Tomcat - Security constraint bypass with HTTP/0.9
GHSA-qq5r-98hh-rxc9 · BIT-tomcat-2026-24733 · CVE-2026-24733
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Improper Input Validation vulnerability in Apache Tomcat.
Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112.
Older, EOL versions are also affected.
Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2026-24733
- WEB https://github.com/apache/tomcat/commit/2e2fa23f2635bbb819759576a2f2f5e64ecf7c5f
- WEB https://github.com/apache/tomcat/commit/6c73d74ff281260d74c836370ff6b82f1da8048b
- WEB https://github.com/apache/tomcat/commit/711b465cf22684a1acf0cb43501cdbbce9b6c5f4
- PACKAGE https://github.com/apache/tomcat
- WEB https://lists.apache.org/thread/6xk3t65qpn1myp618krtfotbjn1qt90f
- WEB https://tomcat.apache.org/security-10.html
- WEB https://tomcat.apache.org/security-11.html
- WEB https://tomcat.apache.org/security-9.html
Ready to move
Start Securing
Free, no credit card | First findings in minutes