Back to Vulnerability Directory
HIGHFixed upstream

CVE-2026-24880

Apache Tomcat: request smuggling through invalid chunk extensions

Technology

Apache Tomcat

CVSS Score

7.5 / 10.0

Affected Versions

11.0.0-M1 to 11.0.18; 10.1.0-M1 to 10.1.52; 9.0.0.M1 to 9.0.115; end of life but named in the record: 8.5.0 to 8.5.100, 7.0.0 to 7.0.109

Upstream Fix

11.0.20; 10.1.53; 9.0.116

Published

April 9, 2026

OSSeva Coverage

Fixed upstream

Description

Tomcat did not validate the contents of HTTP/1.1 chunk extensions. If a reverse proxy in front of Tomcat allowed CRLF sequences in an otherwise valid chunk extension, requests could be smuggled. Rated Low by the Tomcat security team; CISA-ADP scores it 7.5. Fixed in 11.0.20, 10.1.53 and 9.0.116.

Upstream record: NVD · CVE.org

Is your Apache Tomcat deployment affected?

If you're running 11.0.0-M1 to 11.0.18; 10.1.0-M1 to 10.1.52; 9.0.0.M1 to 9.0.115; end of life but named in the record: 8.5.0 to 8.5.100, 7.0.0 to 7.0.109, you need this patch. Book a discovery call to get covered.