GHSA-563x-q5rq-57qp · Severity: high · Ecosystem: maven — Apache Tomcat has an HTTP Request/Response Smuggling vulnerability
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other, unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.20, 10.1.52 or 9.0.116, which fix the issue.
Conclusion & alert: CVE-2026-24880 is rated Moderate Risk (45.6/100): CVSS High severity, with low exploitation likelihood (EPSS 0.21%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-15 | 0.02% | 0.21% | +0.20% |
| 2 | 2026-04-10 | — | 0.02% | — |
Full EPSS history (2 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-563x-q5rq-57qp · Severity: high · Ecosystem: maven — Apache Tomcat has an HTTP Request/Response Smuggling vulnerability
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
not yet assigned | CVE-2026-24880 not yet assigned priority: Debian including 3 source packages (tomcat10, tomcat11, tomcat9), 12 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 12. | https://security-tracker.debian.org/tracker/CVE-2026-24880 |
redhat
|
low | — | https://access.redhat.com/security/cve/CVE-2026-24880 |
suse
|
medium | CVE-2026-24880 severity moderate: SUSE including 33 source package names (tomcat-9.0.117-1.1, tomcat-admin-webapps-9.0.117-1.1, …), 33 product×package rows across 1 product lines (openSUSE Tumbleweed): Fixed 33. | https://www.suse.com/security/cve/CVE-2026-24880/ |
ubuntu
|
medium | CVE-2026-24880 medium priority: Ubuntu including 6 source packages (tomcat10, tomcat11, tomcat6, tomcat7, tomcat8, tomcat9), 33 status rows across 8 suites (bionic, focal, jammy, noble, questing, trusty, upstream, xenial): needs-triage 18, DNE 12, ignored 3. | https://ubuntu.com/security/CVE-2026-24880 |
| URL | Tags |
|---|---|
| https://lists.apache.org/thread/2c682qnlg2tv4o5knlggqbl9yc2gb5sn | Mailing List Vendor Advisory |
| http://www.openwall.com/lists/oss-security/2026/04/09/20 | Mailing List Third Party Advisory |