Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

Apache Tomcat contains a missing encryption of sensitive data vulnerability that allows the bypass of the EncryptInterceptor. This vulnerability can be chained with CVE‑2025‑24813.

Published 3 Aug 2026Updated 3 Aug 20262 sources
CVSS 0.0 △ CISA KEV

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.