https://seclists.org/oss-sec/2026/q3/581: CVE-2026-65637: Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete
Published Aug 25, 2026
·Updated
Affected Software
3 affected components
Apache Tomcat>=11.0.20<=11.0.24
Apache Tomcat>=10.1.53<=10.1.57
Apache Tomcat>=9.0.115<=9.0.120
Frequently Asked Questions
1
Which supported Tomcat release lines require review?
The affected ranges are Tomcat 11.0.20 through 11.0.24, Tomcat 10.1.53 through 10.1.57, and Tomcat 9.0.115 through 9.0.120.
2
Does remediation for CVE-2026-32990 fully address this issue?
No. This issue is identified as an incomplete fix for CVE-2026-32990.