CVE-2025-66614
Apache Tomcat: client certificate verification bypass through virtual host mapping
Technology
Apache Tomcat
CVSS Score
9.1 / 10.0
Affected Versions
11.0.0-M1 to 11.0.14; 10.1.0-M1 to 10.1.49; 9.0.0.M1 to 9.0.112; end of life but known affected: 8.5.0 to 8.5.100
Upstream Fix
11.0.15; 10.1.50; 9.0.113
Published
February 17, 2026
OSSeva Coverage
Fixed upstream
Description
Tomcat did not check that the host name in the TLS SNI extension matched the HTTP Host header. With more than one virtual host, where one host's TLS configuration required client certificate authentication and another's did not, a client could bypass the client certificate requirement by sending different names. It applies only where client certificate authentication is enforced at the connector, not in the web application. Rated Moderate by the Tomcat security team. Fixed in 11.0.15, 10.1.50 and 9.0.113; the fix was completed by CVE-2026-32990 in 11.0.20, 10.1.53 and 9.0.116.
Is your Apache Tomcat deployment affected?
If you're running 11.0.0-M1 to 11.0.14; 10.1.0-M1 to 10.1.49; 9.0.0.M1 to 9.0.112; end of life but known affected: 8.5.0 to 8.5.100, you need this patch. Book a discovery call to get covered.