CVE-2026-32990
Java vulnerability analysis and mitigation

Overview

CVE-2026-32990 is an Improper Input Validation vulnerability in Apache Tomcat resulting from an incomplete fix of CVE-2025-66614. It affects Apache Tomcat versions 11.0.15 through 11.0.19, 10.1.50 through 10.1.52, and 9.0.113 through 9.0.115. The vulnerability was published on April 9, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 5.3 (Medium) and a CVSS v4.0 score of 6.9 (Moderate) (GitHub Advisory, Feedly).

Technical details

The root cause is classified under CWE-20 (Improper Input Validation) and CWE-184 (Incomplete List of Disallowed Inputs), stemming from an incomplete remediation of CVE-2025-66614 (GitHub Advisory). The vulnerability is network-exploitable with low attack complexity, requiring no privileges or user interaction, meaning a remote unauthenticated attacker can send crafted HTTP requests to bypass input validation controls that were intended to be enforced by the prior fix. The specific bypass mechanism relates to input filtering gaps that allow certain disallowed inputs to pass through Tomcat's validation logic. Relevant source code commits addressing the issue are available in the Apache Tomcat repository (commits 021d1f8, 4d0615a, 95f7778) (GitHub Advisory).

Impact

Successful exploitation results in a limited confidentiality impact — an unauthenticated remote attacker may be able to access information they should not be permitted to view, while integrity and availability are not directly affected (GitHub Advisory, Feedly). The scope is limited to the vulnerable Tomcat instance itself, with no direct subsequent system impact identified. Given the incomplete-fix nature of this vulnerability, organizations that applied the CVE-2025-66614 patch but have not yet upgraded to the latest versions remain exposed to the same class of bypass.

Exploitability

As of the time of publication, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.19–0.21%, placing it in the 43rd percentile for exploitation likelihood within 30 days (GitHub Advisory). No threat actor attribution has been reported, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Mitigation and workarounds

Users should upgrade to the patched versions of Apache Tomcat: 11.0.20 (for the 11.x branch), 10.1.53 (for the 10.1.x branch), or 9.0.116 (for the 9.x branch) (GitHub Advisory, Apache Tomcat Security). Red Hat has addressed this issue in Red Hat JBoss Web Server 6.2.2 via RHSA-2026:12194 and RHSA-2026:12195 (Red Hat Bugzilla). IBM has also released fixes for affected products including IBM Business Automation Manager Open Editions, IBM Process Mining, and IBM API Connect (Feedly). No configuration-based workaround has been published; upgrading is the recommended remediation.

Community reactions

The Apache Software Foundation disclosed the vulnerability via the Apache mailing list on April 9, 2026, and Red Hat promptly filed a Bugzilla entry and issued errata (RHSA-2026:12194, RHSA-2026:12195) by April 30, 2026 (Red Hat Bugzilla). HeroDevs published a blog post covering this and related Apache Tomcat vulnerabilities patched in April 2026 (HeroDevs Blog). Community discussion was noted on security mailing lists including oss-sec and the Apache announce list, with general acknowledgment that the incomplete-fix nature of the vulnerability warranted prompt patching.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

tomcat9: 9.0.70-2

Fixed

sid

tomcat9: 9.0.70-2

Fixed

trixie

tomcat9: 9.0.70-2

Fixed

Ubuntu

Affected

bionic (esm-apps)

tomcat7

Not Affected

devel

tomcat9

Not Affected

focal (esm-apps)

tomcat9

Not Affected

jammy

tomcat9

Not Affected

jammy (esm-apps)

tomcat9

Not Affected

noble

tomcat9

Not Affected

noble (esm-apps)

tomcat9

Not Affected

questing

tomcat9

Not Affected

RHEL / CentOS

Fixed

RHEL 9

:appstream:tomcat/tomcat-1:9.0.120-1.el9_8

Fixed

RHEL 10

tomcat9-1:9.0.117-2.el10_2.src

Fixed

SourceThis report was generated using AI

Related Java vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-58400CRITICAL9.1
  • Java logoJava
  • org.geonetwork-opensource:gs-web-app
NoYesSep 03, 2026
CVE-2026-63219HIGH8.6
  • Java logoJava
  • org.geonetwork-opensource:gn-services
NoYesSep 03, 2026
CVE-2026-49832HIGH8
  • Java logoJava
  • org.dspace:dspace-api
NoYesSep 02, 2026
CVE-2026-55864HIGH7.7
  • Java logoJava
  • org.geonetwork-opensource:gn-web-app
NoYesSep 09, 2026
CVE-2026-49833MEDIUM5.5
  • Java logoJava
  • org.dspace:dspace-api
NoYesSep 02, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management