Apache Tomcat vulnerabilities
261 known vulnerabilities affecting apache/tomcat.
Total CVEs
261
CISA KEV
6
actively exploited
Public exploits
55
Exploited in wild
8
Severity breakdown
CRITICAL21HIGH85MEDIUM139LOW16
Vulnerabilities
Page 10 of 14
CVE-2002-1394P4HIGHCVSS 7.5v4.0.0v4.0.1+8 more2003-01-17
CVE-2002-1394 [HIGH] CVE-2002-1394: Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows
Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.
nvd
CVE-2011-5063P4MEDIUMCVSS 4.3v5.5.0v5.5.1+74 more2012-01-14
CVE-2011-5063 [MEDIUM] CVE-2011-5063: The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x befor
The HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 does not check realm values, which might allow remote attackers to bypass intended access restrictions by leveraging the availability of a protection space with weaker authentication or authorization requirements, a different vul
nvd
CVE-2024-52318P4MEDIUMCVSS 6.1v9.0.96v10.1.31+1 more2024-11-18
CVE-2024-52318 [MEDIUM] CWE-326 CVE-2024-52318: Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomc
Incorrect object recycling and reuse vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96.
Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue.
nvd
CVE-2005-2090P4MEDIUMCVSS 4.3v4.1.24v5.0.192005-07-05
CVE-2005-2090 [MEDIUM] CVE-2005-2090: Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison
Jakarta Tomcat 5.0.19 (Coyote/1.1) and Tomcat 4.1.24 (Coyote/1.0) allows remote attackers to poison the web cache, bypass web application firewall protection, and conduct XSS attacks via an HTTP request with both a "Transfer-Encoding: chunked" header and a Content-Length header, which causes Tomcat to incorrectly handle and forward the body of the request in a
nvd
CVE-2026-25854P4MEDIUMCVSS 6.1≥ 9.0.1, < 9.0.116≥ 10.1.0, < 10.1.53+2 more2026-04-09
CVE-2026-25854 [MEDIUM] CWE-601 CVE-2026-25854: Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via th
Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100.
Other, unsupported versions may also be affected
Users are re
nvd
CVE-2011-1475P4MEDIUMCVSS 5.0v7.0.0v7.0.1+10 more2011-04-08
CVE-2011-1475 [MEDIUM] CWE-20 CVE-2011-1475: The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining
The HTTP BIO connector in Apache Tomcat 7.0.x before 7.0.12 does not properly handle HTTP pipelining, which allows remote attackers to read responses intended for other clients in opportunistic circumstances by examining the application data in HTTP packets, related to "a mix-up of responses for requests from different users."
nvd
CVE-2011-3375P4MEDIUMCVSS 5.0v6.0.30v6.0.31+24 more2012-01-19
CVE-2011-3375 [MEDIUM] CWE-200 CVE-2011-3375: Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching
Apache Tomcat 6.0.30 through 6.0.33 and 7.x before 7.0.22 does not properly perform certain caching and recycling operations involving request objects, which allows remote attackers to obtain unintended read access to IP address and HTTP header information in opportunistic circumstances by reading TCP data.
nvd
CVE-2009-2901P4MEDIUMCVSS 4.3v5.5.0v5.5.1+49 more2010-01-28
CVE-2009-2901 [MEDIUM] CWE-264 CVE-2009-2901: The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when auto
The autodeployment process in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20, when autoDeploy is enabled, deploys appBase files that remain from a failed undeploy, which might allow remote attackers to bypass intended authentication requirements via HTTP requests.
nvd
CVE-2011-5064P4MEDIUMCVSS 4.3v5.5.0v5.5.1+74 more2012-01-14
CVE-2011-5064 [MEDIUM] CVE-2011-5064: DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.
DigestAuthenticator.java in the HTTP Digest Access Authentication implementation in Apache Tomcat 5.5.x before 5.5.34, 6.x before 6.0.33, and 7.x before 7.0.12 uses Catalina as the hard-coded server secret (aka private key), which makes it easier for remote attackers to bypass cryptographic protection mechanisms by leveraging knowledge of this string, a diffe
nvd
CVE-2016-0706P4MEDIUMCVSS 4.3v6.0.0v6.0.1+88 more2016-02-25
CVE-2016-0706 [MEDIUM] CWE-200 CVE-2016-0706: Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does
Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows remote authenticated users to bypass intended SecurityManager restrictions and read arbitrary HTTP requests, and c
nvd
CVE-2020-1935P4MEDIUMCVSS 4.8≥ 7.0.0, ≤ 7.0.99≥ 8.5.0, ≤ 8.5.50+2 more2020-02-24
CVE-2020-1935 [MEDIUM] CWE-444 CVE-2020-1935: In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing cod
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encodi
nvd
CVE-2012-2733P4MEDIUMCVSS 5.0v6.0v6.0.0+55 more2012-11-16
CVE-2012-2733 [MEDIUM] CWE-20 CVE-2012-2733: java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat
java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a large amount of header data.
nvd
CVE-2019-17569P4MEDIUMCVSS 4.8≥ 7.0.98, ≤ 7.0.99≥ 8.5.48, ≤ 8.5.50+1 more2020-02-24
CVE-2019-17569 [MEDIUM] CWE-444 CVE-2019-17569: The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 int
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the inval
nvd
CVE-2025-61795P4MEDIUMCVSS 5.3≥ 8.5.0, ≤ 8.5.100≥ 9.0.0, < 9.0.110+3 more2025-10-27
CVE-2025-61795 [MEDIUM] CWE-404 CVE-2025-61795: Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (includi
Improper Resource Shutdown or Release vulnerability in Apache Tomcat.
If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memor
nvd
CVE-2014-0099P4MEDIUMCVSS 4.3≤ 6.0.39v6+89 more2014-05-31
CVE-2014-0099 [MEDIUM] CWE-189 CVE-2014-0099: Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x b
Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allows remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.
nvd
CVE-2015-5174P4MEDIUMCVSS 4.3v6.0.0v6.0.1+80 more2016-02-25
CVE-2015-5174 [MEDIUM] CWE-22 CVE-2015-5174: Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before
Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application in a getResource, getResourceAsStream, or getRe
nvd
CVE-2023-42795P4MEDIUMCVSS 5.3≥ 8.5.0, < 8.5.94≥ 9.0.1, < 9.0.81+4 more2023-10-10
CVE-2023-42795 [MEDIUM] CWE-459 CVE-2023-42795: Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache
Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could
cause Tomcat to skip some parts of the recycling process leading to
information leaking from the curren
nvd
CVE-2024-54677P4MEDIUMCVSS 5.3≥ 9.0.0, < 9.0.98≥ 10.1.0, < 10.1.34+1 more2024-12-17
CVE-2024-54677 [MEDIUM] CWE-400 CVE-2024-54677: Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97.
The following versions were EOL at the time the CVE was created but are
known to be aff
nvd
CVE-2026-32990P4MEDIUMCVSS 5.3≥ 9.0.113, < 9.0.116≥ 10.1.50, < 10.1.53+1 more2026-04-09
CVE-2026-32990 [MEDIUM] CVE-2026-32990: Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614.
Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614.
This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
nvd
CVE-2012-3544P4MEDIUMCVSS 5.0v6.0v6.0.0+57 more2013-06-01
CVE-2012-3544 [MEDIUM] CWE-20 CVE-2012-3544: Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in c
Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.
nvd