#VU122997 Protection mechanism failure in Apache Tomcat - CVE-2026-24733
Published: February 17, 2026 / Updated: February 18, 2026
Apache Tomcat
Apache Foundation
Description
The vulnerability allows a remote attacker to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures when handling HTTP/0.9 requests. If the server is configured to allow HEAD requests to a URI but deny GET requests, an attacker can bypass that constraint on GET requests by sending a (specification invalid) HEAD request.
Remediation
External links
- https://tomcat.apache.org/security-10.html#Fixed_in_Apache_Tomcat_10.1.50
- https://github.com/apache/tomcat/commit/711b465cf22684a1acf0cb43501cdbbce9b6c5f4
- https://github.com/apache/tomcat/commit/6c73d74ff281260d74c836370ff6b82f1da8048b
- https://github.com/apache/tomcat/commit/2e2fa23f2635bbb819759576a2f2f5e64ecf7c5f
- https://tomcat.apache.org/security-9.html#Fixed_in_Apache_Tomcat_9.0.113
- https://tomcat.apache.org/security-11.html#Fixed_in_Apache_Tomcat_11.0.15
- https://lists.apache.org/thread/y5zdwotqzxompqf7133gr43nmk05n142