{"id":"CVE-2025-66614","details":"Improper Input Validation vulnerability.\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112.\n\nThe following versions were EOL at the time the CVE was created but are \nknown to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected.\nTomcat did not validate that the host name provided via the SNI \nextension was the same as the host name provided in the HTTP host header \nfield. If Tomcat was configured with more than one virtual host and the \nTLS configuration for one of those hosts did not require client \ncertificate authentication but another one did, it was possible for a \nclient to bypass the client certificate authentication by sending \ndifferent host names in the SNI extension and the HTTP host header field.\n\n\n\nThe vulnerability only applies if client certificate authentication is \nonly enforced at the Connector. It does not apply if client certificate \nauthentication is enforced at the web application.\n\n\nUsers are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fix the issue.","aliases":["BIT-tomcat-2025-66614","GHSA-fpj8-gq4v-p354"],"modified":"2026-04-29T18:29:34.852057926Z","published":"2026-02-17T19:21:55.310Z","related":["CGA-wrh6-pmqv-3546","SUSE-SU-2026:0877-1","SUSE-SU-2026:0890-1","SUSE-SU-2026:0932-1","SUSE-SU-2026:1058-1","SUSE-SU-2026:1558-1","SUSE-SU-2026:1572-1","SUSE-SU-2026:1603-1","SUSE-SU-2026:1604-1","SUSE-SU-2026:20926-1","SUSE-SU-2026:20982-1","SUSE-SU-2026:21366-1","SUSE-SU-2026:21378-1","SUSE-SU-2026:21379-1","openSUSE-SU-2026:10305-1","openSUSE-SU-2026:10306-1","openSUSE-SU-2026:10307-1","openSUSE-SU-2026:20350-1","openSUSE-SU-2026:20414-1","openSUSE-SU-2026:20444-1","openSUSE-SU-2026:20595-1","openSUSE-SU-2026:20611-1","openSUSE-SU-2026:20612-1"],"references":[{"type":"ADVISORY","url":"https://lists.apache.org/thread/vw6lxtlh2qbqwpb61wd3sv1flm2nttw7"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/tomcat","events":[{"introduced":"3c78e95e36268dfb76db1570f0cf49104fa6eabc"},{"fixed":"1da89d3d01aece456d622548d92055a60ff19c37"},{"introduced":"934df02dc68e72b95a38f372017f1b89b0d13a76"},{"fixed":"cd6d685800b0e46797325866dee2c9a78fc8e69c"},{"introduced":"6c56147c3966fde5ae34aab2b253593e8700a28c"},{"fixed":"692d6ffc5aa75d6804749ffcc14353c6b046fd92"},{"introduced":"0"},{"last_affected":"29b07def810d335012e738b22ab44d4e232b50d1"},{"introduced":"0"},{"last_affected":"10e04de1946981261a734507f4a6d953e2a206fe"},{"introduced":"0"},{"last_affected":"65ddc3a3872ea41ca67fec7b6834c704b6893361"},{"introduced":"0"},{"last_affected":"b5a74e3c7913c560648f0ffedfbbb3ebe4318def"},{"introduced":"0"},{"last_affected":"de128d72af746184e035ff1b53629f08cb141a04"},{"introduced":"0"},{"last_affected":"aac670afe1226e10513021100fce8a12344743c6"},{"introduced":"0"},{"last_affected":"c2c8107f0cea4755497a85990807b883b66f6b57"},{"introduced":"0"},{"last_affected":"8c48678b110f3fbbe66f6dde0e45d2578fa92c29"},{"introduced":"0"},{"last_affected":"9c5edb840d9413c1408e7c191bc0e1bbfcd9e07f"},{"introduced":"0"},{"last_affected":"59e713216cf2256aacc54f6ba627865f356f9e4e"},{"introduced":"0"},{"last_affected":"7dc5e29fe49850102261badf158752d6865311e4"},{"introduced":"0"},{"last_affected":"18b014d8691909be6153ae7db022a6c35f9c93ea"},{"introduced":"0"},{"last_affected":"600dc8ba5d9be7599d29bff83c342213d93b034e"},{"introduced":"0"},{"last_affected":"3bd48aab236e5bf0ed1644e9f0c588fd20e503ab"},{"introduced":"0"},{"last_affected":"642d3dd4d50ea1f03f9827962e4fc982a123bb78"},{"introduced":"0"},{"last_affected":"24566c02fb917a6ca1b6479a60971b0d8acd895c"},{"introduced":"0"},{"last_affected":"cac0e029dcced854eeca7444710e78e412dc2c2a"},{"introduced":"0"},{"last_affected":"c5efed313de1a181f4f9f98f5023117f3b911257"},{"introduced":"0"},{"last_affected":"ab04166fac59fcf9b3be3aab1c8b896842782d4c"},{"introduced":"0"},{"last_affected":"35071e7e52f296b9187b054b0efd74121b7db3bd"},{"introduced":"0"},{"last_affected":"d1dc05e934e089ea8907998cf850760017a0ed82"},{"introduced":"0"},{"last_affected":"fd7f13635e6855f6ba3fead0bf37ba2fbf8b68cf"},{"introduced":"0"},{"last_affected":"c7b84102600d600bcc527560d9c4d10c3fd440ab"},{"introduced":"0"},{"last_affected":"d8ebf61e51b4455e3c226751e492a533f9002d48"},{"introduced":"0"},{"last_affected":"aba238718ac9b149d25feaa9a14ecad3b0e3a5e2"},{"introduced":"0"},{"last_affected":"fe854ab1f111396458d98fa2ab08c693ce9407e1"},{"introduced":"0"},{"last_affected":"45f8fd74cdb96490fab8709263a4d862f0d429cf"},{"introduced":"0"},{"last_affected":"f2ab9ac8bc3f40ee9b2cb50b030c99df927f0429"},{"introduced":"0"},{"last_affected":"dc3639dd7123301ced18dbf4ddf2dca93704870d"},{"introduced":"0"},{"last_affected":"049799677ba307378a256621bb1a7b03f597571c"},{"introduced":"0"},{"last_affected":"d08498a3cefa7206bad791acf019455794f865ea"},{"introduced":"0"},{"last_affected":"faa2582152d9dcbcb444700df340e10a85fc375f"},{"introduced":"0"},{"last_affected":"02e84c839def0228475fad85d0b19abc2f70b03f"},{"introduced":"0"},{"last_affected":"dcf3e81b2e709574971c7a9592614d70c1b55bf7"},{"introduced":"0"},{"last_affected":"02c4004b52be88a04a7372577d56da0f9ed3a7fe"},{"introduced":"0"},{"last_affected":"7a261dff58bc9581317c400b5c0fa4f7ae371fda"},{"introduced":"0"},{"last_affected":"ae9df1bcc169a5b03adea54c8c19ca9bd902e44f"},{"introduced":"0"},{"last_affected":"ff0b6c231b7a1a416688346fdd299a3d6cfb5b64"},{"introduced":"0"},{"last_affected":"0e59fedb28df646930c5aff945159b64d7a52260"},{"introduced":"0"},{"last_affected":"920e86e465fc9db8b0c21b684b42456179308cfd"},{"introduced":"0"},{"last_affected":"8778a44d6323c1066237043a89ab2f36696916b1"},{"introduced":"0"},{"last_affected":"e706972942e2c342e4a37baf5e2596f11e8a0e94"},{"introduced":"0"},{"last_affected":"2a10c8d9110d7b1c7f526f3352648c6b19ba2c52"},{"introduced":"0"},{"last_affected":"51d1031c36c0f2b3ee1e0d14b56228a559144153"},{"introduced":"0"},{"last_affected":"0f3f1e439a040068b741d77777766722e4420ad6"},{"introduced":"0"},{"last_affected":"cd53876fefaa370c31466b0f615e9ad026541a27"},{"introduced":"0"},{"last_affected":"02d546ba3c553c74ff1a99ecc166a6ff9c501ba8"},{"introduced":"0"},{"last_affected":"59c81e30e2f64f5e8c1db78c4860c51850dfb0bd"},{"introduced":"0"},{"last_affected":"06d0e42e6cd70aae860f164c27d16bdfdfcdc496"},{"introduced":"0"},{"last_affected":"ae109f6248e00a1952f706d6941ff930ad4466e1"},{"introduced":"0"},{"last_affected":"5a67c7c58d8caf24969093e6423b7f0b43df2f6a"},{"introduced":"0"},{"last_affected":"de45b3f200602b98cde70debe7f656bef0bb5fa2"},{"introduced":"0"},{"last_affected":"9108a1f6776f7211f5cd27e80b7b5a6e98116b01"},{"introduced":"0"},{"last_affected":"a22029c7147b83e4fbced16add744903245d1147"},{"introduced":"0"},{"last_affected":"ca6ea22e9b6c47df1db85e9af80f80431c3ea19e"},{"introduced":"0"},{"last_affected":"110bc36637569f7e9d191d21ac8600a8667cfc94"},{"introduced":"0"},{"last_affected":"eee0dbb29048a60ee2c85ebcb9abb1750046c0bf"},{"introduced":"0"},{"last_affected":"19e301275f23056e3c46ab296c87cf6e16fbe68f"},{"introduced":"0"},{"last_affected":"4b03c23ad60e678c1d1a85df815fb6cd8d14ca67"},{"introduced":"0"},{"last_affected":"c400bf727cbc10198d3f52c29849d18660050b0c"},{"introduced":"0"},{"last_affected":"2acc5c10a303d6ae7a28c2959432aef98ae29016"},{"introduced":"0"},{"last_affected":"6c03e2dc6390ccb3dbe714889706fcad2f08f4c5"},{"introduced":"0"},{"last_affected":"2bf2c6a691ad9f2cf68363123419909cebbb308a"},{"introduced":"0"},{"last_affected":"5301df36454fcf22081108e25199f29904cadc79"},{"introduced":"0"},{"last_affected":"fafe3dc7a63c12fbb45aa076c90d6a9e7f77e5c8"},{"introduced":"0"},{"last_affected":"e9935d107776339a4a48cf4e32195a763fbf8379"},{"introduced":"0"},{"last_affected":"8afe2647d7801172cc304f4a47d8aad9646d2985"},{"introduced":"0"},{"last_affected":"3b6de549bdf4f6486c39daa0ae8e4d4b7475b1f6"},{"introduced":"0"},{"last_affected":"06977fbea3c82c3d29e544203983dd3b49a632f1"},{"introduced":"0"},{"last_affected":"9ce010463a93138d596c54c67b11cdb35fc8244a"},{"introduced":"0"},{"last_affected":"eb9d5f0b70a1b84fa18af30eaf358cfa9e4b87ae"},{"introduced":"0"},{"last_affected":"434400d882a20e12ea03855f4bd93451bd3362c6"},{"introduced":"0"},{"last_affected":"de714a23642a4d0baef342db6762a7f7a550d82c"}],"database_specific":{"versions":[{"introduced":"9.0.1"},{"fixed":"9.0.113"},{"introduced":"10.1.1"},{"fixed":"10.1.50"},{"introduced":"11.0.1"},{"fixed":"11.0.15"},{"introduced":"0"},{"last_affected":"9.0.0-milestone1"},{"introduced":"0"},{"last_affected":"9.0.0-milestone10"},{"introduced":"0"},{"last_affected":"9.0.0-milestone11"},{"introduced":"0"},{"last_affected":"9.0.0-milestone12"},{"introduced":"0"},{"last_affected":"9.0.0-milestone13"},{"introduced":"0"},{"last_affected":"9.0.0-milestone14"},{"introduced":"0"},{"last_affected":"9.0.0-milestone15"},{"introduced":"0"},{"last_affected":"9.0.0-milestone16"},{"introduced":"0"},{"last_affected":"9.0.0-milestone17"},{"introduced":"0"},{"last_affected":"9.0.0-milestone18"},{"introduced":"0"},{"last_affected":"9.0.0-milestone19"},{"introduced":"0"},{"last_affected":"9.0.0-milestone2"},{"introduced":"0"},{"last_affected":"9.0.0-milestone20"},{"introduced":"0"},{"last_affected":"9.0.0-milestone21"},{"introduced":"0"},{"last_affected":"9.0.0-milestone22"},{"introduced":"0"},{"last_affected":"9.0.0-milestone23"},{"introduced":"0"},{"last_affected":"9.0.0-milestone24"},{"introduced":"0"},{"last_affected":"9.0.0-milestone25"},{"introduced":"0"},{"last_affected":"9.0.0-milestone26"},{"introduced":"0"},{"last_affected":"9.0.0-milestone27"},{"introduced":"0"},{"last_affected":"9.0.0-milestone3"},{"introduced":"0"},{"last_affected":"9.0.0-milestone4"},{"introduced":"0"},{"last_affected":"9.0.0-milestone5"},{"introduced":"0"},{"last_affected":"9.0.0-milestone6"},{"introduced":"0"},{"last_affected":"9.0.0-milestone7"},{"introduced":"0"},{"last_affected":"9.0.0-milestone8"},{"introduced":"0"},{"last_affected":"9.0.0-milestone9"},{"introduced":"0"},{"last_affected":"10.1.0-milestone1"},{"introduced":"0"},{"last_affected":"10.1.0-milestone10"},{"introduced":"0"},{"last_affected":"10.1.0-milestone11"},{"introduced":"0"},{"last_affected":"10.1.0-milestone12"},{"introduced":"0"},{"last_affected":"10.1.0-milestone13"},{"introduced":"0"},{"last_affected":"10.1.0-milestone14"},{"introduced":"0"},{"last_affected":"10.1.0-milestone15"},{"introduced":"0"},{"last_affected":"10.1.0-milestone16"},{"introduced":"0"},{"last_affected":"10.1.0-milestone17"},{"introduced":"0"},{"last_affected":"10.1.0-milestone18"},{"introduced":"0"},{"last_affected":"10.1.0-milestone19"},{"introduced":"0"},{"last_affected":"10.1.0-milestone2"},{"introduced":"0"},{"last_affected":"10.1.0-milestone20"},{"introduced":"0"},{"last_affected":"10.1.0-milestone3"},{"introduced":"0"},{"last_affected":"10.1.0-milestone4"},{"introduced":"0"},{"last_affected":"10.1.0-milestone5"},{"introduced":"0"},{"last_affected":"10.1.0-milestone6"},{"introduced":"0"},{"last_affected":"10.1.0-milestone7"},{"introduced":"0"},{"last_affected":"10.1.0-milestone8"},{"introduced":"0"},{"last_affected":"10.1.0-milestone9"},{"introduced":"0"},{"last_affected":"11.0.0-milestone1"},{"introduced":"0"},{"last_affected":"11.0.0-milestone10"},{"introduced":"0"},{"last_affected":"11.0.0-milestone11"},{"introduced":"0"},{"last_affected":"11.0.0-milestone12"},{"introduced":"0"},{"last_affected":"11.0.0-milestone13"},{"introduced":"0"},{"last_affected":"11.0.0-milestone14"},{"introduced":"0"},{"last_affected":"11.0.0-milestone15"},{"introduced":"0"},{"last_affected":"11.0.0-milestone16"},{"introduced":"0"},{"last_affected":"11.0.0-milestone17"},{"introduced":"0"},{"last_affected":"11.0.0-milestone18"},{"introduced":"0"},{"last_affected":"11.0.0-milestone19"},{"introduced":"0"},{"last_affected":"11.0.0-milestone2"},{"introduced":"0"},{"last_affected":"11.0.0-milestone20"},{"introduced":"0"},{"last_affected":"11.0.0-milestone21"},{"introduced":"0"},{"last_affected":"11.0.0-milestone22"},{"introduced":"0"},{"last_affected":"11.0.0-milestone23"},{"introduced":"0"},{"last_affected":"11.0.0-milestone24"},{"introduced":"0"},{"last_affected":"11.0.0-milestone25"},{"introduced":"0"},{"last_affected":"11.0.0-milestone26"},{"introduced":"0"},{"last_affected":"11.0.0-milestone3"},{"introduced":"0"},{"last_affected":"11.0.0-milestone4"},{"introduced":"0"},{"last_affected":"11.0.0-milestone5"},{"introduced":"0"},{"last_affected":"11.0.0-milestone6"},{"introduced":"0"},{"last_affected":"11.0.0-milestone7"},{"introduced":"0"},{"last_affected":"11.0.0-milestone8"},{"introduced":"0"},{"last_affected":"11.0.0-milestone9"}]}}],"versions":["10.1.0-M1","10.1.0-M10","10.1.0-M11","10.1.0-M12","10.1.0-M13","10.1.0-M14","10.1.0-M15","10.1.0-M16","10.1.0-M17","10.1.0-M18","10.1.0-M19","10.1.0-M2","10.1.0-M20","10.1.0-M3","10.1.0-M4","10.1.0-M5","10.1.0-M6","10.1.0-M7","10.1.0-M8","10.1.0-M9","11.0.0-M1","11.0.0-M10","11.0.0-M11","11.0.0-M12","11.0.0-M13","11.0.0-M14","11.0.0-M15","11.0.0-M16","11.0.0-M17","11.0.0-M18","11.0.0-M19","11.0.0-M2","11.0.0-M20","11.0.0-M21","11.0.0-M22","11.0.0-M23","11.0.0-M24","11.0.0-M25","11.0.0-M26","11.0.0-M3","11.0.0-M4","11.0.0-M5","11.0.0-M6","11.0.0-M7","11.0.0-M8","11.0.0-M9","9.0.0-M1","9.0.0-M10","9.0.0-M11","9.0.0-M12","9.0.0-M13","9.0.0-M14","9.0.0-M15","9.0.0-M16","9.0.0-M17","9.0.0-M18","9.0.0-M19","9.0.0-M2","9.0.0-M20","9.0.0-M21","9.0.0-M22","9.0.0-M23","9.0.0-M24","9.0.0-M25","9.0.0-M26","9.0.0-M27","9.0.0-M3","9.0.0-M4","9.0.0-M5","9.0.0-M6","9.0.0-M7","9.0.0-M8","9.0.0-M9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-66614.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N"}]}