CVE-2026-24880: does Apache's upgrade advice actually apply to your Tomcat? Detects the fix by class presence, not version comparison. Covers 7.0/8.0/8.5/9.0/10.0/10.1/11.0 lines.
java security tomcat cve eol sca apache-tomcat vulnerability-scanner tomcat7 tomcat9 dependency-check tomcat-security http-request-smuggling request-smuggling chunked-encoding patch-verification cwe-444 tomcat85 cve-2026-24880 ghsa-563x-q5rq-57qp
-
Updated
Sep 1, 2026 - Java