CVE-2026-65637

Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete

Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120. Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.


We have discovered 516 live websites that are affected by CVE-2026-65637.

Run a Free Instant Scan




Affected Software

Product  Apache Tomcat
Category Web Servers
Vulnerable Domains516 live websites (7.23% of Apache Tomcat install base)
Vulnerable Versions
  • from 9.0.115 through 9.0.120
  • from 10.1.53 through 10.1.57
  • from 11.0.20 through 11.0.24
Vulnerable Versions Count15 versions ( 3.98% of all versions)


Common Weakness Enumeration

CWE-20 Improper Input Validation



Details

  • Published - Aug 25, 2026
  • Updated - Aug 26, 2026

Credits

  • Parag Ambildhuke (https://github.com/paragxa) (finder)

Website Distribution by Country

Number of websites using CVE-2026-65637
United States198 websites



Germany89 websites
China29 websites
France22 websites
Canada21 websites
Netherlands21 websites
Italy17 websites
GB14 websites
Sweden9 websites
India8 websites

Website Distribution by TLD

Number of websites using CVE-2026-65637
.com151 websites
.de75 websites
.edu55 websites
.org42 websites
.it19 websites
.nl17 websites
.net17 websites
.ca7 websites
.at6 websites
.se6 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-65637

Top websites that are affected by CVE-2026-65637. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***.***.edu United States***
**.***.*****.*****.***.com United States**,***
*****.********.com United States**,***
*********.**********.com United States**,***
***.*******.com United States**,***
***.*********.edu United States**,***
*******.*********.com United States***,***
***.*****.**.edu United States***,***
***************.***.uk GB***,***
***********.***********.de Germany***,***
See full domain list

FAQ

CVE-2026-65637 is Improper Input Validation in Apache Tomcat
A total of 516 websites have been identified as vulnerable to CVE-2026-65637, based on global website indexing conducted by WebTechSurvey.
The Apache Tomcat is affected by the CVE-2026-65637 vulnerability.
Apache Tomcat versions up to and including 11.0.24 are vulnerable to CVE-2026-65637.