Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2025-66614

Apache Tomcat: client certificate verification bypass through virtual host mapping

Technology

Apache Tomcat

CVSS Score

9.1 / 10.0

Affected Versions

11.0.0-M1 to 11.0.14; 10.1.0-M1 to 10.1.49; 9.0.0.M1 to 9.0.112; end of life but known affected: 8.5.0 to 8.5.100

Upstream Fix

11.0.15; 10.1.50; 9.0.113

Published

February 17, 2026

OSSeva Coverage

Fixed upstream

Description

Tomcat did not check that the host name in the TLS SNI extension matched the HTTP Host header. With more than one virtual host, where one host's TLS configuration required client certificate authentication and another's did not, a client could bypass the client certificate requirement by sending different names. It applies only where client certificate authentication is enforced at the connector, not in the web application. Rated Moderate by the Tomcat security team. Fixed in 11.0.15, 10.1.50 and 9.0.113; the fix was completed by CVE-2026-32990 in 11.0.20, 10.1.53 and 9.0.116.

Upstream record: NVD · CVE.org

Is your Apache Tomcat deployment affected?

If you're running 11.0.0-M1 to 11.0.14; 10.1.0-M1 to 10.1.49; 9.0.0.M1 to 9.0.112; end of life but known affected: 8.5.0 to 8.5.100, you need this patch. Book a discovery call to get covered.