CVE-2025-66614 | Apache Tomcat up to 8.5.100/9.0.112/10.1.49/11.0.14 TLS Configuration certificate validation (WID-SEC-2026-0443)
A vulnerability was found in Apache Tomcat up to 8.5.100/9.0.112/10.1.49/11.0.14. It has been declared as critical. The affected element is an unknown function of the component TLS Configuration Handler. Such manipulation leads to improper certificate validation. This vulnerability only affects products that are no longer supported by the maintainer.
This vulnerability is uniquely identified as CVE-2025-66614. The attack can be launched remotely. No exploit exists.
It is recommended to upgrade the affected component.