Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Other, unsupported versions may also be affected.
Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Apr 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 09 Apr 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other, unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue. | |
| Title | Apache Tomcat: Request smuggling via invalid chunk extension | |
| Weaknesses | CWE-444 | |
| References |
|
Status: PUBLISHED
Assigner: apache
Published:
Updated: 2026-04-09T23:15:44.782Z
Reserved: 2026-01-27T18:06:58.294Z
Link: CVE-2026-24880
No data.
Status : Received
Published: 2026-04-09T20:16:24.060
Modified: 2026-04-10T00:16:25.563
Link: CVE-2026-24880
No data.
OpenCVE Enrichment
No data.