{"id":"CVE-2026-24733","details":"Improper Input Validation vulnerability in Apache Tomcat.\n\n\nTomcat did not limit HTTP/0.9 requests to the GET method. If a security \nconstraint was configured to allow HEAD requests to a URI but deny GET \nrequests, the user could bypass that constraint on GET requests by \nsending a (specification invalid) HEAD request using HTTP/0.9.\n\n\nThis issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112.\n\n\nOlder, EOL versions are also affected.\n\nUsers are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.","aliases":["BIT-tomcat-2026-24733","GHSA-qq5r-98hh-rxc9"],"modified":"2026-04-16T04:38:34.143264920Z","published":"2026-02-17T19:21:56.820Z","related":["CGA-cx5v-2w43-7c54","SUSE-SU-2026:0877-1","SUSE-SU-2026:0890-1","SUSE-SU-2026:0922-1","SUSE-SU-2026:0932-1","SUSE-SU-2026:1058-1","SUSE-SU-2026:20926-1","SUSE-SU-2026:20982-1","openSUSE-SU-2026:10305-1","openSUSE-SU-2026:10306-1","openSUSE-SU-2026:10307-1","openSUSE-SU-2026:20350-1","openSUSE-SU-2026:20414-1","openSUSE-SU-2026:20444-1"],"references":[{"type":"ADVISORY","url":"https://lists.apache.org/thread/6xk3t65qpn1myp618krtfotbjn1qt90f"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/tomcat","events":[{"introduced":"3c78e95e36268dfb76db1570f0cf49104fa6eabc"},{"fixed":"1da89d3d01aece456d622548d92055a60ff19c37"},{"introduced":"934df02dc68e72b95a38f372017f1b89b0d13a76"},{"fixed":"cd6d685800b0e46797325866dee2c9a78fc8e69c"},{"introduced":"6c56147c3966fde5ae34aab2b253593e8700a28c"},{"fixed":"692d6ffc5aa75d6804749ffcc14353c6b046fd92"},{"introduced":"0"},{"last_affected":"29b07def810d335012e738b22ab44d4e232b50d1"},{"introduced":"0"},{"last_affected":"10e04de1946981261a734507f4a6d953e2a206fe"},{"introduced":"0"},{"last_affected":"65ddc3a3872ea41ca67fec7b6834c704b6893361"},{"introduced":"0"},{"last_affected":"b5a74e3c7913c560648f0ffedfbbb3ebe4318def"},{"introduced":"0"},{"last_affected":"de128d72af746184e035ff1b53629f08cb141a04"},{"introduced":"0"},{"last_affected":"aac670afe1226e10513021100fce8a12344743c6"},{"introduced":"0"},{"last_affected":"c2c8107f0cea4755497a85990807b883b66f6b57"},{"introduced":"0"},{"last_affected":"8c48678b110f3fbbe66f6dde0e45d2578fa92c29"},{"introduced":"0"},{"last_affected":"9c5edb840d9413c1408e7c191bc0e1bbfcd9e07f"},{"introduced":"0"},{"last_affected":"59e713216cf2256aacc54f6ba627865f356f9e4e"},{"introduced":"0"},{"last_affected":"7dc5e29fe49850102261badf158752d6865311e4"},{"introduced":"0"},{"last_affected":"18b014d8691909be6153ae7db022a6c35f9c93ea"},{"introduced":"0"},{"last_affected":"600dc8ba5d9be7599d29bff83c342213d93b034e"},{"introduced":"0"},{"last_affected":"3bd48aab236e5bf0ed1644e9f0c588fd20e503ab"},{"introduced":"0"},{"last_affected":"642d3dd4d50ea1f03f9827962e4fc982a123bb78"},{"introduced":"0"},{"last_affected":"24566c02fb917a6ca1b6479a60971b0d8acd895c"},{"introduced":"0"},{"last_affected":"cac0e029dcced854eeca7444710e78e412dc2c2a"},{"introduced":"0"},{"last_affected":"c5efed313de1a181f4f9f98f5023117f3b911257"},{"introduced":"0"},{"last_affected":"ab04166fac59fcf9b3be3aab1c8b896842782d4c"},{"introduced":"0"},{"last_affected":"35071e7e52f296b9187b054b0efd74121b7db3bd"},{"introduced":"0"},{"last_affected":"d1dc05e934e089ea8907998cf850760017a0ed82"},{"introduced":"0"},{"last_affected":"fd7f13635e6855f6ba3fead0bf37ba2fbf8b68cf"},{"introduced":"0"},{"last_affected":"c7b84102600d600bcc527560d9c4d10c3fd440ab"},{"introduced":"0"},{"last_affected":"d8ebf61e51b4455e3c226751e492a533f9002d48"},{"introduced":"0"},{"last_affected":"aba238718ac9b149d25feaa9a14ecad3b0e3a5e2"},{"introduced":"0"},{"last_affected":"fe854ab1f111396458d98fa2ab08c693ce9407e1"},{"introduced":"0"},{"last_affected":"45f8fd74cdb96490fab8709263a4d862f0d429cf"},{"introduced":"0"},{"last_affected":"b0b074b683ed2e09ff9e9755825bfce83d303a93"},{"introduced":"0"},{"last_affected":"9826be4c8368c94eab1e804b456867ca1cb766c3"},{"introduced":"0"},{"last_affected":"d971ce1bdf8b8e8de93fb41454f4ce2e815ee936"},{"introduced":"0"},{"last_affected":"eb684224706fe1d8ef5610c8d79dc403e1038393"},{"introduced":"0"},{"last_affected":"772df65db45cfccc2aad33b9b51ef9ab14c19626"},{"introduced":"0"},{"last_affected":"b3a208c6d6d01c553178c5e718e750b0eb318151"},{"introduced":"0"},{"last_affected":"27f7ef8cd0c637b700d564ec20f6ff92901f6b5c"},{"introduced":"0"},{"last_affected":"c549413165721180b15f62033c1be6c5970028fd"},{"introduced":"0"},{"last_affected":"b3f5e0d88336d81a61a767fc10ab06930c9587ee"},{"introduced":"0"},{"last_affected":"6f143d19d151620cd0bfe9ec2ffa429e36ad0e45"},{"introduced":"0"},{"last_affected":"59c81e30e2f64f5e8c1db78c4860c51850dfb0bd"},{"introduced":"0"},{"last_affected":"06d0e42e6cd70aae860f164c27d16bdfdfcdc496"},{"introduced":"0"},{"last_affected":"ae109f6248e00a1952f706d6941ff930ad4466e1"},{"introduced":"0"},{"last_affected":"5a67c7c58d8caf24969093e6423b7f0b43df2f6a"},{"introduced":"0"},{"last_affected":"de45b3f200602b98cde70debe7f656bef0bb5fa2"},{"introduced":"0"},{"last_affected":"9108a1f6776f7211f5cd27e80b7b5a6e98116b01"},{"introduced":"0"},{"last_affected":"a22029c7147b83e4fbced16add744903245d1147"},{"introduced":"0"},{"last_affected":"ca6ea22e9b6c47df1db85e9af80f80431c3ea19e"},{"introduced":"0"},{"last_affected":"110bc36637569f7e9d191d21ac8600a8667cfc94"},{"introduced":"0"},{"last_affected":"eee0dbb29048a60ee2c85ebcb9abb1750046c0bf"},{"introduced":"0"},{"last_affected":"19e301275f23056e3c46ab296c87cf6e16fbe68f"},{"introduced":"0"},{"last_affected":"4b03c23ad60e678c1d1a85df815fb6cd8d14ca67"},{"introduced":"0"},{"last_affected":"c400bf727cbc10198d3f52c29849d18660050b0c"},{"introduced":"0"},{"last_affected":"2acc5c10a303d6ae7a28c2959432aef98ae29016"},{"introduced":"0"},{"last_affected":"6c03e2dc6390ccb3dbe714889706fcad2f08f4c5"},{"introduced":"0"},{"last_affected":"2bf2c6a691ad9f2cf68363123419909cebbb308a"},{"introduced":"0"},{"last_affected":"5301df36454fcf22081108e25199f29904cadc79"},{"introduced":"0"},{"last_affected":"fafe3dc7a63c12fbb45aa076c90d6a9e7f77e5c8"},{"introduced":"0"},{"last_affected":"e9935d107776339a4a48cf4e32195a763fbf8379"},{"introduced":"0"},{"last_affected":"8afe2647d7801172cc304f4a47d8aad9646d2985"},{"introduced":"0"},{"last_affected":"3b6de549bdf4f6486c39daa0ae8e4d4b7475b1f6"},{"introduced":"0"},{"last_affected":"06977fbea3c82c3d29e544203983dd3b49a632f1"},{"introduced":"0"},{"last_affected":"9ce010463a93138d596c54c67b11cdb35fc8244a"},{"introduced":"0"},{"last_affected":"eb9d5f0b70a1b84fa18af30eaf358cfa9e4b87ae"},{"introduced":"0"},{"last_affected":"434400d882a20e12ea03855f4bd93451bd3362c6"},{"introduced":"0"},{"last_affected":"de714a23642a4d0baef342db6762a7f7a550d82c"}],"database_specific":{"versions":[{"introduced":"9.0.1"},{"fixed":"9.0.113"},{"introduced":"10.1.1"},{"fixed":"10.1.50"},{"introduced":"11.0.1"},{"fixed":"11.0.15"},{"introduced":"0"},{"last_affected":"9.0.0-milestone1"},{"introduced":"0"},{"last_affected":"9.0.0-milestone10"},{"introduced":"0"},{"last_affected":"9.0.0-milestone11"},{"introduced":"0"},{"last_affected":"9.0.0-milestone12"},{"introduced":"0"},{"last_affected":"9.0.0-milestone13"},{"introduced":"0"},{"last_affected":"9.0.0-milestone14"},{"introduced":"0"},{"last_affected":"9.0.0-milestone15"},{"introduced":"0"},{"last_affected":"9.0.0-milestone16"},{"introduced":"0"},{"last_affected":"9.0.0-milestone17"},{"introduced":"0"},{"last_affected":"9.0.0-milestone18"},{"introduced":"0"},{"last_affected":"9.0.0-milestone19"},{"introduced":"0"},{"last_affected":"9.0.0-milestone2"},{"introduced":"0"},{"last_affected":"9.0.0-milestone20"},{"introduced":"0"},{"last_affected":"9.0.0-milestone21"},{"introduced":"0"},{"last_affected":"9.0.0-milestone22"},{"introduced":"0"},{"last_affected":"9.0.0-milestone23"},{"introduced":"0"},{"last_affected":"9.0.0-milestone24"},{"introduced":"0"},{"last_affected":"9.0.0-milestone25"},{"introduced":"0"},{"last_affected":"9.0.0-milestone26"},{"introduced":"0"},{"last_affected":"9.0.0-milestone27"},{"introduced":"0"},{"last_affected":"9.0.0-milestone3"},{"introduced":"0"},{"last_affected":"9.0.0-milestone4"},{"introduced":"0"},{"last_affected":"9.0.0-milestone5"},{"introduced":"0"},{"last_affected":"9.0.0-milestone6"},{"introduced":"0"},{"last_affected":"9.0.0-milestone7"},{"introduced":"0"},{"last_affected":"9.0.0-milestone8"},{"introduced":"0"},{"last_affected":"9.0.0-milestone9"},{"introduced":"0"},{"last_affected":"10.0.0-milestone1"},{"introduced":"0"},{"last_affected":"10.0.0-milestone10"},{"introduced":"0"},{"last_affected":"10.0.0-milestone2"},{"introduced":"0"},{"last_affected":"10.0.0-milestone3"},{"introduced":"0"},{"last_affected":"10.0.0-milestone4"},{"introduced":"0"},{"last_affected":"10.0.0-milestone5"},{"introduced":"0"},{"last_affected":"10.0.0-milestone6"},{"introduced":"0"},{"last_affected":"10.0.0-milestone7"},{"introduced":"0"},{"last_affected":"10.0.0-milestone8"},{"introduced":"0"},{"last_affected":"10.0.0-milestone9"},{"introduced":"0"},{"last_affected":"11.0.0-milestone1"},{"introduced":"0"},{"last_affected":"11.0.0-milestone10"},{"introduced":"0"},{"last_affected":"11.0.0-milestone11"},{"introduced":"0"},{"last_affected":"11.0.0-milestone12"},{"introduced":"0"},{"last_affected":"11.0.0-milestone13"},{"introduced":"0"},{"last_affected":"11.0.0-milestone14"},{"introduced":"0"},{"last_affected":"11.0.0-milestone15"},{"introduced":"0"},{"last_affected":"11.0.0-milestone16"},{"introduced":"0"},{"last_affected":"11.0.0-milestone17"},{"introduced":"0"},{"last_affected":"11.0.0-milestone18"},{"introduced":"0"},{"last_affected":"11.0.0-milestone19"},{"introduced":"0"},{"last_affected":"11.0.0-milestone2"},{"introduced":"0"},{"last_affected":"11.0.0-milestone20"},{"introduced":"0"},{"last_affected":"11.0.0-milestone21"},{"introduced":"0"},{"last_affected":"11.0.0-milestone22"},{"introduced":"0"},{"last_affected":"11.0.0-milestone23"},{"introduced":"0"},{"last_affected":"11.0.0-milestone24"},{"introduced":"0"},{"last_affected":"11.0.0-milestone25"},{"introduced":"0"},{"last_affected":"11.0.0-milestone26"},{"introduced":"0"},{"last_affected":"11.0.0-milestone3"},{"introduced":"0"},{"last_affected":"11.0.0-milestone4"},{"introduced":"0"},{"last_affected":"11.0.0-milestone5"},{"introduced":"0"},{"last_affected":"11.0.0-milestone6"},{"introduced":"0"},{"last_affected":"11.0.0-milestone7"},{"introduced":"0"},{"last_affected":"11.0.0-milestone8"},{"introduced":"0"},{"last_affected":"11.0.0-milestone9"}]}}],"versions":["10.0.0-M1","10.0.0-M10","10.0.0-M2","10.0.0-M3","10.0.0-M4","10.0.0-M5","10.0.0-M6","10.0.0-M7","10.0.0-M8","10.0.0-M9","11.0.0-M1","11.0.0-M10","11.0.0-M11","11.0.0-M12","11.0.0-M13","11.0.0-M14","11.0.0-M15","11.0.0-M16","11.0.0-M17","11.0.0-M18","11.0.0-M19","11.0.0-M2","11.0.0-M20","11.0.0-M21","11.0.0-M22","11.0.0-M23","11.0.0-M24","11.0.0-M25","11.0.0-M26","11.0.0-M3","11.0.0-M4","11.0.0-M5","11.0.0-M6","11.0.0-M7","11.0.0-M8","11.0.0-M9","9.0.0-M1","9.0.0-M10","9.0.0-M11","9.0.0-M12","9.0.0-M13","9.0.0-M14","9.0.0-M15","9.0.0-M16","9.0.0-M17","9.0.0-M18","9.0.0-M19","9.0.0-M2","9.0.0-M20","9.0.0-M21","9.0.0-M22","9.0.0-M23","9.0.0-M24","9.0.0-M25","9.0.0-M26","9.0.0-M27","9.0.0-M3","9.0.0-M4","9.0.0-M5","9.0.0-M6","9.0.0-M7","9.0.0-M8","9.0.0-M9"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-24733.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}