CVE-2025-66614

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Description

A certificate validation flaw has been found in Apache Tomcat. omcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field. The vulnerability only applies if client certificate authentication is only enforced at the Connector. It does not apply if client certificate authentication is enforced at the web application.

Metrics

Severity
high
no public PoC known
14.4 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-04-04 16:29 UTC
CWE-20

Weakness classes (CWE)

  • CWE-20Class

    Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    cwe.mitre.org →

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • bitnami

    tomcat10.0.0

  • bitnami

    tomcat10.1.0

  • bitnami

    tomcat11.0.0

  • bitnami

    tomcat8.5.0

  • bitnami

    tomcat9.0.83

References & sources

Linked CVEs

IDCVE-2025-66614