9.1

CVE-2025-66614

Apache Tomcat: Client certificate verification bypass due to virtual host mapping

Improper Input Validation vulnerability.

This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112.

The following versions were EOL at the time the CVE was created but are 
known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected.
Tomcat did not validate that the host name provided via the SNI 
extension was the same as the host name provided in the HTTP host header 
field. If Tomcat was configured with more than one virtual host and the 
TLS configuration for one of those hosts did not require client 
certificate authentication but another one did, it was possible for a 
client to bypass the client certificate authentication by sending 
different host names in the SNI extension and the HTTP host header field.



The vulnerability only applies if client certificate authentication is 
only enforced at the Connector. It does not apply if client certificate 
authentication is enforced at the web application.


Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fix the issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Apache ≫ Tomcat Version >= 9.0.1 < 9.0.113
Apache ≫ Tomcat Version >= 10.1.1 < 10.1.50
Apache ≫ Tomcat Version >= 11.0.1 < 11.0.15
Apache ≫ Tomcat Version 9.0.0 Update milestone1
Apache ≫ Tomcat Version 9.0.0 Update milestone10
Apache ≫ Tomcat Version 9.0.0 Update milestone11
Apache ≫ Tomcat Version 9.0.0 Update milestone12
Apache ≫ Tomcat Version 9.0.0 Update milestone13
Apache ≫ Tomcat Version 9.0.0 Update milestone14
Apache ≫ Tomcat Version 9.0.0 Update milestone15
Apache ≫ Tomcat Version 9.0.0 Update milestone16
Apache ≫ Tomcat Version 9.0.0 Update milestone17
Apache ≫ Tomcat Version 9.0.0 Update milestone18
Apache ≫ Tomcat Version 9.0.0 Update milestone19
Apache ≫ Tomcat Version 9.0.0 Update milestone2
Apache ≫ Tomcat Version 9.0.0 Update milestone20
Apache ≫ Tomcat Version 9.0.0 Update milestone21
Apache ≫ Tomcat Version 9.0.0 Update milestone22
Apache ≫ Tomcat Version 9.0.0 Update milestone23
Apache ≫ Tomcat Version 9.0.0 Update milestone24
Apache ≫ Tomcat Version 9.0.0 Update milestone25
Apache ≫ Tomcat Version 9.0.0 Update milestone26
Apache ≫ Tomcat Version 9.0.0 Update milestone27
Apache ≫ Tomcat Version 9.0.0 Update milestone3
Apache ≫ Tomcat Version 9.0.0 Update milestone4
Apache ≫ Tomcat Version 9.0.0 Update milestone5
Apache ≫ Tomcat Version 9.0.0 Update milestone6
Apache ≫ Tomcat Version 9.0.0 Update milestone7
Apache ≫ Tomcat Version 9.0.0 Update milestone8
Apache ≫ Tomcat Version 9.0.0 Update milestone9
Apache ≫ Tomcat Version 10.1.0 Update milestone1
Apache ≫ Tomcat Version 10.1.0 Update milestone10
Apache ≫ Tomcat Version 10.1.0 Update milestone11
Apache ≫ Tomcat Version 10.1.0 Update milestone12
Apache ≫ Tomcat Version 10.1.0 Update milestone13
Apache ≫ Tomcat Version 10.1.0 Update milestone14
Apache ≫ Tomcat Version 10.1.0 Update milestone15
Apache ≫ Tomcat Version 10.1.0 Update milestone16
Apache ≫ Tomcat Version 10.1.0 Update milestone17
Apache ≫ Tomcat Version 10.1.0 Update milestone18
Apache ≫ Tomcat Version 10.1.0 Update milestone19
Apache ≫ Tomcat Version 10.1.0 Update milestone2
Apache ≫ Tomcat Version 10.1.0 Update milestone20
Apache ≫ Tomcat Version 10.1.0 Update milestone3
Apache ≫ Tomcat Version 10.1.0 Update milestone4
Apache ≫ Tomcat Version 10.1.0 Update milestone5
Apache ≫ Tomcat Version 10.1.0 Update milestone6
Apache ≫ Tomcat Version 10.1.0 Update milestone7
Apache ≫ Tomcat Version 10.1.0 Update milestone8
Apache ≫ Tomcat Version 10.1.0 Update milestone9
Apache ≫ Tomcat Version 11.0.0 Update milestone1
Apache ≫ Tomcat Version 11.0.0 Update milestone10
Apache ≫ Tomcat Version 11.0.0 Update milestone11
Apache ≫ Tomcat Version 11.0.0 Update milestone12
Apache ≫ Tomcat Version 11.0.0 Update milestone13
Apache ≫ Tomcat Version 11.0.0 Update milestone14
Apache ≫ Tomcat Version 11.0.0 Update milestone15
Apache ≫ Tomcat Version 11.0.0 Update milestone16
Apache ≫ Tomcat Version 11.0.0 Update milestone17
Apache ≫ Tomcat Version 11.0.0 Update milestone18
Apache ≫ Tomcat Version 11.0.0 Update milestone19
Apache ≫ Tomcat Version 11.0.0 Update milestone2
Apache ≫ Tomcat Version 11.0.0 Update milestone20
Apache ≫ Tomcat Version 11.0.0 Update milestone21
Apache ≫ Tomcat Version 11.0.0 Update milestone22
Apache ≫ Tomcat Version 11.0.0 Update milestone23
Apache ≫ Tomcat Version 11.0.0 Update milestone24
Apache ≫ Tomcat Version 11.0.0 Update milestone25
Apache ≫ Tomcat Version 11.0.0 Update milestone26
Apache ≫ Tomcat Version 11.0.0 Update milestone3
Apache ≫ Tomcat Version 11.0.0 Update milestone4
Apache ≫ Tomcat Version 11.0.0 Update milestone5
Apache ≫ Tomcat Version 11.0.0 Update milestone6
Apache ≫ Tomcat Version 11.0.0 Update milestone7
Apache ≫ Tomcat Version 11.0.0 Update milestone8
Apache ≫ Tomcat Version 11.0.0 Update milestone9
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.24% 0.142
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA-ADP 7.6 2.8 4.7
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L
CWE-20 Improper Input Validation

The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

CWE-295 Improper Certificate Validation

The product does not validate, or incorrectly validates, a certificate.

https://lists.apache.org/thread/vw6lxtlh2qbqwpb61wd3sv1flm2nttw7
Vendor Advisory
Mailing List