
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-32990 is an Improper Input Validation vulnerability in Apache Tomcat resulting from an incomplete fix of CVE-2025-66614. It affects Apache Tomcat versions 11.0.15 through 11.0.19, 10.1.50 through 10.1.52, and 9.0.113 through 9.0.115. The vulnerability was published on April 9, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 score of 6.9 (Moderate) (GitHub Advisory, Feedly).
The root cause is classified under CWE-20 (Improper Input Validation) and CWE-184 (Incomplete List of Disallowed Inputs), stemming from an incomplete remediation of CVE-2025-66614 (GitHub Advisory). The vulnerability is network-exploitable with low attack complexity, requiring no privileges or user interaction, meaning a remote unauthenticated attacker can send crafted HTTP requests to bypass input validation controls that were intended to be enforced by the prior fix. The specific bypass mechanism relates to input filtering gaps that allow certain disallowed inputs to pass through Tomcat's validation logic. Relevant source code commits addressing the issue are available in the Apache Tomcat repository (commits 021d1f8, 4d0615a, 95f7778) (GitHub Advisory).
Successful exploitation results in a limited confidentiality impact — an unauthenticated remote attacker may be able to access information they should not be permitted to view, while integrity and availability are not directly affected (GitHub Advisory, Feedly). The scope is limited to the vulnerable Tomcat instance itself, with no direct subsequent system impact identified. Given the incomplete-fix nature of this vulnerability, organizations that applied the CVE-2025-66614 patch but have not yet upgraded to the latest versions remain exposed to the same class of bypass.
As of the time of publication, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.19–0.21%, placing it in the 43rd percentile for exploitation likelihood within 30 days (GitHub Advisory). No threat actor attribution has been reported, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.
Users should upgrade to the patched versions of Apache Tomcat: 11.0.20 (for the 11.x branch), 10.1.53 (for the 10.1.x branch), or 9.0.116 (for the 9.x branch) (GitHub Advisory, Apache Tomcat Security). Red Hat has addressed this issue in Red Hat JBoss Web Server 6.2.2 via RHSA-2026:12194 and RHSA-2026:12195 (Red Hat Bugzilla). IBM has also released fixes for affected products including IBM Business Automation Manager Open Editions, IBM Process Mining, and IBM API Connect (Feedly). No configuration-based workaround has been published; upgrading is the recommended remediation.
The Apache Software Foundation disclosed the vulnerability via the Apache mailing list on April 9, 2026, and Red Hat promptly filed a Bugzilla entry and issued errata (RHSA-2026:12194, RHSA-2026:12195) by April 30, 2026 (Red Hat Bugzilla). HeroDevs published a blog post covering this and related Apache Tomcat vulnerabilities patched in April 2026 (HeroDevs Blog). Community discussion was noted on security mailing lists including oss-sec and the Apache announce list, with general acknowledgment that the incomplete-fix nature of the vulnerability warranted prompt patching.
Fix availability across major Linux distributions and their releases.
bionic (esm-apps)
tomcat7
devel
tomcat9
focal (esm-apps)
tomcat9
jammy
tomcat9
jammy (esm-apps)
tomcat9
noble
tomcat9
noble (esm-apps)
tomcat9
questing
tomcat9
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."