Improper access control in Apache Tomcat - CVE-2026-65637
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass strict SNI validation.
The vulnerability exists due to improper access control in the HTTP/2 request handling when processing requests without an authority field. A remote attacker can send a specially crafted HTTP/2 request to bypass strict SNI validation.
The issue is related to an incomplete fix for a previous vulnerability.