CVE-2026-24880
Apache Tomcat: request smuggling through invalid chunk extensions
Technology
Apache Tomcat
CVSS Score
7.5 / 10.0
Affected Versions
11.0.0-M1 to 11.0.18; 10.1.0-M1 to 10.1.52; 9.0.0.M1 to 9.0.115; end of life but named in the record: 8.5.0 to 8.5.100, 7.0.0 to 7.0.109
Upstream Fix
11.0.20; 10.1.53; 9.0.116
Published
April 9, 2026
OSSeva Coverage
Fixed upstream
Description
Tomcat did not validate the contents of HTTP/1.1 chunk extensions. If a reverse proxy in front of Tomcat allowed CRLF sequences in an otherwise valid chunk extension, requests could be smuggled. Rated Low by the Tomcat security team; CISA-ADP scores it 7.5. Fixed in 11.0.20, 10.1.53 and 9.0.116.
Is your Apache Tomcat deployment affected?
If you're running 11.0.0-M1 to 11.0.18; 10.1.0-M1 to 10.1.52; 9.0.0.M1 to 9.0.115; end of life but named in the record: 8.5.0 to 8.5.100, 7.0.0 to 7.0.109, you need this patch. Book a discovery call to get covered.