Apache Tomcat Vulnerability
Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.
CVSS Score
9.8
CRITICAL
Published
04 Aug 2026 00:00
Modified
N/A
Vendor
Apache
Product
Tomcat
Source
CIRCL
Affected Versions
Fix
Vendor Patch / Mitigation Available
Weaknesses (CWE)
CWE-311
Affected Systems
Apache
Tomcat
Apache
Tomcat
ActiveMQ
External Links
KEV Status
Known Exploited Vulnerability