CVE-2026-24733

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Description

A flaw was found in Tomcat. An improper input validation vulnerability allows an attacker to bypass security constraints. Specifically, if a security constraint is configured to permit HEAD requests to a URI but deny GET requests, a malformed or specification invalid HEAD request using the HTTP/0.9 protocol can bypass the intended denial rule, enabling an attacker to access resources that should be protected.

Metrics

Severity
high
no public PoC known
40.9 %
High — this CVE ranks above the median of all CVEs scored today (rank ≥ 36%).
0.5 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-04-04 16:29 UTC
CWE-20

Weakness classes (CWE)

  • CWE-20Class

    Improper Input Validation

    The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

    cwe.mitre.org →

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • bitnami

    tomcat10.0.0

  • bitnami

    tomcat10.1.0

  • bitnami

    tomcat11.0.0

  • bitnami

    tomcat8.5.0

  • bitnami

    tomcat9.0.83

References & sources

Linked CVEs

IDCVE-2026-24733