{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-02T07:04:00.677","vulnerabilities":[{"cve":{"id":"CVE-2026-24733","sourceIdentifier":"security@apache.org","published":"2026-02-17T19:21:56.820","lastModified":"2026-03-11T16:16:29.773","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Improper Input Validation vulnerability in Apache Tomcat.\n\n\nTomcat did not limit HTTP/0.9 requests to the GET method. If a security \nconstraint was configured to allow HEAD requests to a URI but deny GET \nrequests, the user could bypass that constraint on GET requests by \nsending a (specification invalid) HEAD request using HTTP/0.9.\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112.\n\n\nOlder, EOL versions are also affected.\n\nUsers are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue."},{"lang":"es","value":"Vulnerabilidad de validación de entrada inadecuada en Apache Tomcat.\n\nTomcat no limitaba las solicitudes HTTP/0.9 al método GET. Si una restricción de seguridad estaba configurada para permitir solicitudes HEAD a una URI pero denegar solicitudes GET, el usuario podía eludir esa restricción en las solicitudes GET enviando una solicitud HEAD (inválida según la especificación) usando HTTP/0.9.\n\nEste problema afecta a Apache Tomcat: desde 11.0.0-M1 hasta 11.0.14, desde 10.1.0-M1 hasta 10.1.49, desde 9.0.0.M1 hasta 9.0.112.\n\nLas versiones más antiguas, EOL, también están afectadas.\n\nSe recomienda a los usuarios actualizar a la versión 11.0.15 o posterior, 10.1.50 o posterior o 9.0.113 o posterior, lo que soluciona el problema."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N","baseScore":3.7,"baseSeverity":"LOW","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":1.4},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"NONE"},"exploitabilityScore":3.9,"impactScore":2.5}]},"weaknesses":[{"source":"security@apache.org","type":"Secondary","description":[{"lang":"en","value":"CWE-20"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-noinfo"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*","versionStartIncluding":"9.0.1","versionEndExcluding":"9.0.113","matchCriteriaId":"B76D20D5-8512-40CD-8B59-B0D4FBFBE7F3"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*","versionStartIncluding":"10.1.1","versionEndExcluding":"10.1.50","matchCriteriaId":"8A9BCC2E-EB49-4C74-B150-564AEDE6D8BB"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:*:*:*:*:*:*:*:*","versionStartIncluding":"11.0.1","versionEndExcluding":"11.0.15","matchCriteriaId":"9307BA8D-D3BD-41B0-89F3-124704B7EA6A"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone1:*:*:*:*:*:*","matchCriteriaId":"9D0689FE-4BC0-4F53-8C79-34B21F9B86C2"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone10:*:*:*:*:*:*","matchCriteriaId":"89B129B2-FB6F-4EF9-BF12-E589A87996CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone11:*:*:*:*:*:*","matchCriteriaId":"8B6787B6-54A8-475E-BA1C-AB99334B2535"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone12:*:*:*:*:*:*","matchCriteriaId":"EABB6FBC-7486-44D5-A6AD-FFF1D3F677E1"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone13:*:*:*:*:*:*","matchCriteriaId":"E10C03BC-EE6B-45B2-83AE-9E8DFB58D7DB"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone14:*:*:*:*:*:*","matchCriteriaId":"8A6DA0BE-908C-4DA8-A191-A0113235E99A"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone15:*:*:*:*:*:*","matchCriteriaId":"39029C72-28B4-46A4-BFF5-EC822CFB2A4C"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone16:*:*:*:*:*:*","matchCriteriaId":"1A2E05A3-014F-4C4D-81E5-88E725FBD6AD"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone17:*:*:*:*:*:*","matchCriteriaId":"166C533C-0833-41D5-99B6-17A4FAB3CAF0"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone18:*:*:*:*:*:*","matchCriteriaId":"D3768C60-21FA-4B92-B98C-C3A2602D1BC4"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone19:*:*:*:*:*:*","matchCriteriaId":"DDD510FA-A2E4-4BAF-A0DE-F4E5777E9325"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone2:*:*:*:*:*:*","matchCriteriaId":"9F542E12-6BA8-4504-A494-DA83E7E19BD5"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone20:*:*:*:*:*:*","matchCriteriaId":"C2409CC7-6A85-4A66-A457-0D62B9895DC1"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone21:*:*:*:*:*:*","matchCriteriaId":"B392A7E5-4455-4B1C-8FAC-AE6DDC70689E"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone22:*:*:*:*:*:*","matchCriteriaId":"EF411DDA-2601-449A-9046-D250419A0E1A"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone23:*:*:*:*:*:*","matchCriteriaId":"D7D8F2F4-AFE2-47EA-A3FD-79B54324DE02"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone24:*:*:*:*:*:*","matchCriteriaId":"1B4FBF97-DE16-4E5E-BE19-471E01818D40"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone25:*:*:*:*:*:*","matchCriteriaId":"3B266B1E-24B5-47EE-A421-E0E3CC0C7471"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone26:*:*:*:*:*:*","matchCriteriaId":"29614C3A-6FB3-41C7-B56E-9CC3F45B04F0"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone27:*:*:*:*:*:*","matchCriteriaId":"C6AB156C-8FF6-4727-AF75-590D0DCB3F9D"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone3:*:*:*:*:*:*","matchCriteriaId":"C0C5F004-F7D8-45DB-B173-351C50B0EC16"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone4:*:*:*:*:*:*","matchCriteriaId":"D1902D2E-1896-4D3D-9E1C-3A675255072C"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone5:*:*:*:*:*:*","matchCriteriaId":"49AAF4DF-F61D-47A8-8788-A21E317A145D"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone6:*:*:*:*:*:*","matchCriteriaId":"454211D0-60A2-4661-AECA-4C0121413FEB"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone7:*:*:*:*:*:*","matchCriteriaId":"0686F977-889F-4960-8E0B-7784B73A7F2D"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone8:*:*:*:*:*:*","matchCriteriaId":"558703AE-DB5E-4DFF-B497-C36694DD7B24"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:9.0.0:milestone9:*:*:*:*:*:*","matchCriteriaId":"ED6273F2-1165-47A4-8DD7-9E9B2472941B"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:10.0.0:milestone1:*:*:*:*:*:*","matchCriteriaId":"90CD7E85-4FF9-4158-AC78-4BFCBC882A65"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:10.0.0:milestone10:*:*:*:*:*:*","matchCriteriaId":"83B9FF07-1B93-4F8C-AC56-7CA74E61B724"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:10.0.0:milestone2:*:*:*:*:*:*","matchCriteriaId":"7EA56B52-1015-40CD-B10C-393768094269"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:10.0.0:milestone3:*:*:*:*:*:*","matchCriteriaId":"501B0D4A-D636-4736-979B-D5023599CEFB"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:10.0.0:milestone4:*:*:*:*:*:*","matchCriteriaId":"94E7764F-BF9E-463E-B446-A9A8DB92BB97"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:10.0.0:milestone5:*:*:*:*:*:*","matchCriteriaId":"53A9F7EE-AF2A-43E5-B708-0198784AB45A"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:10.0.0:milestone6:*:*:*:*:*:*","matchCriteriaId":"AC872C5F-63AF-4BB8-8629-334FC9704AE8"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:10.0.0:milestone7:*:*:*:*:*:*","matchCriteriaId":"94B95C95-DF3E-49C1-9CA0-4474DD7EF7B8"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:10.0.0:milestone8:*:*:*:*:*:*","matchCriteriaId":"310B0163-01DE-40DA-A2EA-FFA4A6100037"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:10.0.0:milestone9:*:*:*:*:*:*","matchCriteriaId":"75420449-A951-4133-A5F1-4C01F2DF843B"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone1:*:*:*:*:*:*","matchCriteriaId":"D1AA7FF6-E8E7-4BF6-983E-0A99B0183008"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone10:*:*:*:*:*:*","matchCriteriaId":"57088BDD-A136-45EF-A8A1-2EBF79CEC2CE"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone11:*:*:*:*:*:*","matchCriteriaId":"B32D1D7A-A04F-444E-8F45-BB9A9E4B0199"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone12:*:*:*:*:*:*","matchCriteriaId":"0092FB35-3B00-484F-A24D-7828396A4FF6"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone13:*:*:*:*:*:*","matchCriteriaId":"CB557E88-FA9D-4B69-AA6F-EAEE7F9B01AC"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone14:*:*:*:*:*:*","matchCriteriaId":"72D3C6F1-84FA-4F82-96C1-9A8DA1C1F30F"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone15:*:*:*:*:*:*","matchCriteriaId":"3521C81B-37D9-48FC-9540-D0D333B9A4A4"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone16:*:*:*:*:*:*","matchCriteriaId":"02A84634-A8F2-4BA9-B9F3-BEF36AEC5480"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone17:*:*:*:*:*:*","matchCriteriaId":"ECBBC1F1-C86B-40AF-B740-A99F6B27682A"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone18:*:*:*:*:*:*","matchCriteriaId":"9D2206B2-F3FF-43F2-B3E2-3CAAC64C691D"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone19:*:*:*:*:*:*","matchCriteriaId":"0495A538-4102-40D0-A35C-0179CFD52A9D"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone2:*:*:*:*:*:*","matchCriteriaId":"2AAD52CE-94F5-4F98-A027-9A7E68818CB6"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone20:*:*:*:*:*:*","matchCriteriaId":"77BA6600-0890-4BA1-B447-EC1746BAB4FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone21:*:*:*:*:*:*","matchCriteriaId":"7914D26B-CBD6-4846-9BD3-403708D69319"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone22:*:*:*:*:*:*","matchCriteriaId":"123C6285-03BE-49FC-B821-8BDB25D02863"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone23:*:*:*:*:*:*","matchCriteriaId":"8A28C2E2-B7BC-46CE-94E4-AE3EF172AA47"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone24:*:*:*:*:*:*","matchCriteriaId":"069B0D8E-8223-4C4E-A834-C6235D6C3450"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone25:*:*:*:*:*:*","matchCriteriaId":"E6282085-5716-4874-B0B0-180ECDEE128F"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone26:*:*:*:*:*:*","matchCriteriaId":"899B6FF0-8701-47E7-8EDA-428A6D48786D"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone3:*:*:*:*:*:*","matchCriteriaId":"F1F981F5-035A-4EDD-8A9F-481EE8BC7FF7"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone4:*:*:*:*:*:*","matchCriteriaId":"03A171AF-2EC8-4422-912C-547CDB58CAAA"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone5:*:*:*:*:*:*","matchCriteriaId":"538E68C4-0BA4-495F-AEF8-4EF6EE7963CF"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone6:*:*:*:*:*:*","matchCriteriaId":"49350A6E-5E1D-45B2-A874-3B8601B3ADCC"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone7:*:*:*:*:*:*","matchCriteriaId":"5F50942F-DF54-46C0-8371-9A476DD3EEA3"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone8:*:*:*:*:*:*","matchCriteriaId":"D12C2C95-B79F-4AA4-8CE3-99A3EE7991AB"},{"vulnerable":true,"criteria":"cpe:2.3:a:apache:tomcat:11.0.0:milestone9:*:*:*:*:*:*","matchCriteriaId":"98792138-DD56-42DF-9612-3BDC65EEC117"}]}]}],"references":[{"url":"https://lists.apache.org/thread/6xk3t65qpn1myp618krtfotbjn1qt90f","source":"security@apache.org","tags":["Mailing List","Vendor Advisory"]}]}}]}