StackRadar

CVE-2026-24733

Medium

Advisory

Published 17 Feb 2026In the index since 6 Sept 2026
Severity
Medium
worst across findings
CVSS
6.9
base score, highest
EPSS
0.005
41st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
40
of 17,781 indexed, latest versions
Container images
32
deployed by those charts
Fix available
3 of 3
affected packages

Apache Tomcat - Security constraint bypass with HTTP/0.9

Carried by container images the latest versions of 40 of 17,781 indexed charts deploy, on 32 images.

Affected packageAffected versionsFixed inImages
tomcat-coyotemaven6.0.48, 7.0.69, 7.0.109, 8.0.38+22 more9.0.113, 10.1.50, 11.0.1532
Apache Tomcatbitnami9.0.809.0.1131
tomcatbitnami9.0.80-19.0.1131
OSV records
BIT-tomcat-2026-24733GHSA-qq5r-98hh-rxc9

Charts affected

40 by stars
ChartLatestAffected imagesRadar Score
guacamoleberyju-org1.4.21 of 3See more

guacamole beryju-org 1.4.2

1 of the 3 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
tomcat-coyote@9.0.106
9.0.113

Open the chart page →

3,606
camunda-bpm-platformcamunda-community-hub7.6.111 of 1See more

camunda-bpm-platform camunda-community-hub 7.6.11

1 of the 1 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
camunda/camunda-bpm-platform:latestbcc5bb0542df
tomcat-coyote@10.1.43
10.1.50

Open the chart page →

1,154
guacamoledmunozv04Verified publisher0.3.41 of 2See more

guacamole dmunozv04 0.3.4

1 of the 2 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
tomcat-coyote@9.0.106
9.0.113

Open the chart page →

3,606
jira-softwaremoxVerified publisher2.7.11 of 3See more

jira-software mox 2.7.1

1 of the 3 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
atlassian/jira-software:9.7.264a75aa4ec4e
tomcat-coyote@9.0.73
9.0.113

Open the chart page →

8,636
guacamolehalkeye0.2.11 of 3See more

guacamole halkeye 0.2.1

1 of the 3 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
guacamole/guacamole:1.1.0333a7f40c145
tomcat-coyote@8.5.41
9.0.113

Open the chart page →

4,839
hivedmwm-bigdataVerified publisher0.1.63 of 5See more

hive dmwm-bigdata 0.1.6

3 of the 5 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
tomcat-coyote@6.0.48
9.0.113
gradiant/hdfs:2.7.73b28784ba41f
tomcat-coyote@6.0.48
9.0.113
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
tomcat-coyote@6.0.48
9.0.113

Open the chart page →

20,837
hive-metastoreslamdev0.0.51 of 2See more

hive-metastore slamdev 0.0.5

1 of the 2 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
tomcat-coyote@8.5.43
9.0.113

Open the chart page →

8,198
structurizrvirtualrootVerified publisher0.5.01 of 1See more

structurizr virtualroot 0.5.0

1 of the 1 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
structurizr/onpremises:2025.11.094b5ffb5119c8
tomcat-coyote@10.1.41
10.1.50

Open the chart page →

4,378
vrijbrpvrijbrpVerified publisher0.1.52 of 5See more

vrijbrp vrijbrp 0.1.5

2 of the 5 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
vrijbrp/balie:developbc85c89530b9
tomcat-coyote@9.0.84
9.0.113
vrijbrp/balie-ws:developc6603cb829ea
tomcat-coyote@9.0.84
9.0.113

Open the chart page →

8,811
hadoopcloudnativeapp1.1.01 of 1See more

hadoop cloudnativeapp 1.1.0

1 of the 1 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
danisla/hadoop:2.9.0255ba2dd739b
tomcat-coyote@6.0.48
9.0.113

Open the chart page →

5,772
hbasedmwm-bigdataVerified publisher0.1.61 of 5See more

hbase dmwm-bigdata 0.1.6

1 of the 5 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
gradiant/hdfs:2.7.73b28784ba41f
tomcat-coyote@6.0.48
9.0.113

Open the chart page →

13,392
hive-metastoredmwm-bigdataVerified publisher0.1.31 of 2See more

hive-metastore dmwm-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
tomcat-coyote@6.0.48
9.0.113

Open the chart page →

6,882
opentsdbdmwm-bigdataVerified publisher0.1.71 of 6See more

opentsdb dmwm-bigdata 0.1.7

1 of the 6 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
gradiant/hdfs:2.7.73b28784ba41f
tomcat-coyote@6.0.48
9.0.113

Open the chart page →

17,511
hbasegradiant-bigdataVerified publisher0.1.61 of 5See more

hbase gradiant-bigdata 0.1.6

1 of the 5 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
gradiant/hdfs:2.7.73b28784ba41f
tomcat-coyote@6.0.48
9.0.113

Open the chart page →

13,392
guacamolehelmforgeVerified publisher1.5.21 of 5See more

guacamole helmforge 1.5.2

1 of the 5 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
guacamole/guacamole:1.6.0f344085e618b
tomcat-coyote@9.0.106
9.0.113

Open the chart page →

8,716
hadoopmiuler1.2.21 of 1See more

hadoop miuler 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
danisla/hadoop:2.9.0255ba2dd739b
tomcat-coyote@6.0.48
9.0.113

Open the chart page →

5,772
apispringbootHelmapispringboot0.1.01 of 1See more

apispringbootHelm apispringboot 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
rabeh/apibootspring:1.0941007b6946e
tomcat-coyote@10.1.16
10.1.50

Open the chart page →

6,187
authorizationassist-iot-authorisation0.1.01 of 2See more

authorization assist-iot-authorisation 0.1.0

1 of the 2 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
assistiot/authorization_svr:latestdb9361dad79b
tomcat-coyote@7.0.109
9.0.113

Open the chart page →

5,537
dashboard-pui9assist-iot-tactile-dashboard0.2.01 of 3See more

dashboard-pui9 assist-iot-tactile-dashboard 0.2.0

1 of the 3 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
tomcat-coyote@9.0.65
9.0.113

Open the chart page →

4,145
axelor-open-suiteaxelor-open-suiteVerified publisher7.2.581 of 2See more

axelor-open-suite axelor-open-suite 7.2.58

1 of the 2 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
tomcat-coyote@9.0.80
Apache Tomcat@9.0.80
tomcat@9.0.80-1
9.0.113
9.0.113
9.0.113

Open the chart page →

9,722
castlemockcnieg2.0.11 of 1See more

castlemock cnieg 2.0.1

1 of the 1 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
castlemock/castlemock:latestb7f3f1527ba9
tomcat-coyote@11.0.5
11.0.15

Open the chart page →

4,578
guacamolegabibbo970.3.01 of 3See more

guacamole gabibbo97 0.3.0

1 of the 3 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
guacamole/guacamole:1.3.0739cb6820ae8
tomcat-coyote@8.5.61
9.0.113

Open the chart page →

6,412
openkmgeek-cookbookVerified publisher4.2.01 of 1See more

openkm geek-cookbook 4.2.0

1 of the 1 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
openkm/openkm-ce:6.3.113bc465a7461b
tomcat-coyote@8.5.69
9.0.113

Open the chart page →

27,949
pretend-youre-xyzzygeek-cookbookVerified publisher3.4.21 of 1See more

pretend-youre-xyzzy geek-cookbook 3.4.2

1 of the 1 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
emcniece/dockeryourxyzzy:404eccbccc15c
tomcat-coyote@7.0.69
9.0.113

Open the chart page →

581
video-analytics-demogpu-operator0.1.91 of 3See more

video-analytics-demo gpu-operator 0.1.9

1 of the 3 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
anguda/ant-media:2.5c435285fc241
tomcat-coyote@8.5.82
9.0.113

Open the chart page →

15,722
hdfsgradiant-bigdataVerified publisher0.1.101 of 2See more

hdfs gradiant-bigdata 0.1.10

1 of the 2 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
gradiant/hdfs:2.7.73b28784ba41f
tomcat-coyote@6.0.48
9.0.113

Open the chart page →

7,073
hivegradiant-bigdataVerified publisher0.1.63 of 5See more

hive gradiant-bigdata 0.1.6

3 of the 5 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
tomcat-coyote@6.0.48
9.0.113
gradiant/hdfs:2.7.73b28784ba41f
tomcat-coyote@6.0.48
9.0.113
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
tomcat-coyote@6.0.48
9.0.113

Open the chart page →

20,837
hive-metastoregradiant-bigdataVerified publisher0.1.31 of 2See more

hive-metastore gradiant-bigdata 0.1.3

1 of the 2 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
bde2020/hive:2.3.2-postgresql-metastore620267768985
tomcat-coyote@6.0.48
9.0.113

Open the chart page →

6,882
opentsdbgradiant-bigdataVerified publisher0.1.71 of 6See more

opentsdb gradiant-bigdata 0.1.7

1 of the 6 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
gradiant/hdfs:2.7.73b28784ba41f
tomcat-coyote@6.0.48
9.0.113

Open the chart page →

17,511
hapi-fhirhapi-fhirVerified publisher0.1.01 of 1See more

hapi-fhir hapi-fhir 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
tomcat-coyote@8.0.38
9.0.113

Open the chart page →

6,362
printserverhmediadeVerified publisher1.0.21 of 4See more

printserver hmediade 1.0.2

1 of the 4 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
hmediade/printserver:latest481a552c8e1c
tomcat-coyote@9.0.85
9.0.113

Open the chart page →

10,839
freeipaimprowisedVerified publisher0.4.11 of 1See more

freeipa improwised 0.4.1

1 of the 1 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
freeipa/freeipa-server:fedora-37-4.10.1c87d77342bf5
tomcat-coyote@9.0.82
9.0.113

Open the chart page →

1,218
tomcatkubesphereVerified publisher0.4.0-r11 of 2See more

tomcat kubesphere 0.4.0-r1

1 of the 2 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
library/tomcat:8.5.41-alpine04feaf74f8bb
tomcat-coyote@8.5.41
9.0.113

Open the chart page →

1,383
crowdmoxVerified publisher2.4.31 of 3See more

crowd mox 2.4.3

1 of the 3 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
atlassian/crowd:5.2.2ebf761c7d437
tomcat-coyote@9.0.82
9.0.113

Open the chart page →

5,663
cdn-remoteopencord0.2.41 of 3See more

cdn-remote opencord 0.2.4

1 of the 3 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
tomcat-coyote@8.5.38
9.0.113

Open the chart page →

63,223
iparedhat-cop1.3.91 of 1See more

ipa redhat-cop 1.3.9

1 of the 1 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
quay.io/freeipa/freeipa-server:fedora-39-4.11.1d422ee50c2c3
tomcat-coyote@9.0.83
9.0.113

Open the chart page →

951
guacamolesergiotocaliniVerified publisher1.0.01 of 2See more

guacamole sergiotocalini 1.0.0

1 of the 2 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
guacamole/guacamole:1.5.50f62f6d17ab3
tomcat-coyote@8.5.98
9.0.113

Open the chart page →

5,456
atlassian-confluencesomeblackmagic3.4.11 of 1See more

atlassian-confluence someblackmagic 3.4.1

1 of the 1 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
atlassian/confluence-server:7.10.03b9222ab32ef
tomcat-coyote@9.0.40
9.0.113

Open the chart page →

13,605
atlassian-jirasomeblackmagic3.3.21 of 1See more

atlassian-jira someblackmagic 3.3.2

1 of the 1 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
atlassian/jira-software:8.14.037bc46cbec1a
tomcat-coyote@8.5.57
9.0.113

Open the chart page →

13,079
umsappstacksimplifyVerified publisher1.0.01 of 3See more

umsapp stacksimplify 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-24733.

Container imageDigestPackageFixed in
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
tomcat-coyote@8.0.51
9.0.113

Open the chart page →

6,101

Container images carrying it

32 by charts deploying them

A fixed version is listed for 3 of the 3 affected packages.

Container imageDigestPackageFixed inUsed by
gradiant/hdfs:2.7.73b28784ba41f
tomcat-coyote@6.0.48
9.0.113
7
bde2020/hive:2.3.2-postgresql-metastore620267768985
tomcat-coyote@6.0.48
9.0.113
4
guacamole/guacamole:1.6.0f344085e618b
tomcat-coyote@9.0.106
9.0.113
3
danisla/hadoop:2.9.0255ba2dd739b
tomcat-coyote@6.0.48
9.0.113
2
gradiant/hive:2.3.2-postgresql-metastoreaae4f8a21f8b
tomcat-coyote@6.0.48
9.0.113
2
anguda/ant-media:2.5c435285fc241
tomcat-coyote@8.5.82
9.0.113
1
assistiot/authorization_svr:latestdb9361dad79b
tomcat-coyote@7.0.109
9.0.113
1
assistiot/tacticle_dashboard:api-lateste4414cb72dc4
tomcat-coyote@9.0.65
9.0.113
1
atlassian/confluence-server:7.10.03b9222ab32ef
tomcat-coyote@9.0.40
9.0.113
1
atlassian/crowd:5.2.2ebf761c7d437
tomcat-coyote@9.0.82
9.0.113
1
atlassian/jira-software:8.14.037bc46cbec1a
tomcat-coyote@8.5.57
9.0.113
1
atlassian/jira-software:9.7.264a75aa4ec4e
tomcat-coyote@9.0.73
9.0.113
1
camunda/camunda-bpm-platform:latestbcc5bb0542df
tomcat-coyote@10.1.43
10.1.50
1
castlemock/castlemock:latestb7f3f1527ba9
tomcat-coyote@11.0.5
11.0.15
1
emcniece/dockeryourxyzzy:404eccbccc15c
tomcat-coyote@7.0.69
9.0.113
1
freeipa/freeipa-server:fedora-37-4.10.1c87d77342bf5
tomcat-coyote@9.0.82
9.0.113
1
guacamole/guacamole:1.5.50f62f6d17ab3
tomcat-coyote@8.5.98
9.0.113
1
guacamole/guacamole:1.1.0333a7f40c145
tomcat-coyote@8.5.41
9.0.113
1
guacamole/guacamole:1.3.0739cb6820ae8
tomcat-coyote@8.5.61
9.0.113
1
hmediade/printserver:latest481a552c8e1c
tomcat-coyote@9.0.85
9.0.113
1
library/tomcat:8.5.41-alpine04feaf74f8bb
tomcat-coyote@8.5.41
9.0.113
1
omecproject/cdn-antmedia:1.0.0b4ae7d0d6b74
tomcat-coyote@8.5.38
9.0.113
1
openkm/openkm-ce:6.3.113bc465a7461b
tomcat-coyote@8.5.69
9.0.113
1
pmoscode/axelor-open-suite:v7.2.57a58f4d762f5c
tomcat-coyote@9.0.80
Apache Tomcat@9.0.80
tomcat@9.0.80-1
9.0.113
9.0.113
9.0.113
1
polyakov/hapi-fhir-jpaserver-example:latestdbcef69146b8
tomcat-coyote@8.0.38
9.0.113
1
rabeh/apibootspring:1.0941007b6946e
tomcat-coyote@10.1.16
10.1.50
1
slamdev/apache-hive:2.3.9-2.10.1b4b029c9b15f
tomcat-coyote@8.5.43
9.0.113
1
structurizr/onpremises:2025.11.094b5ffb5119c8
tomcat-coyote@10.1.41
10.1.50
1
vrijbrp/balie:developbc85c89530b9
tomcat-coyote@9.0.84
9.0.113
1
vrijbrp/balie-ws:developc6603cb829ea
tomcat-coyote@9.0.84
9.0.113
1
ghcr.io/stacksimplify/kube-usermgmt-webapp:1.0.0-mysqldb41b45003c6b6
tomcat-coyote@8.0.51
9.0.113
1
quay.io/freeipa/freeipa-server:fedora-39-4.11.1d422ee50c2c3
tomcat-coyote@9.0.83
9.0.113
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.