cbcvebase.

Apache Tomcat vulnerabilities

272 known vulnerabilities affecting apache/tomcat.

Total CVEs
272
CISA KEV
7
actively exploited
Public exploits
55
Exploited in wild
9
Severity breakdown
CRITICAL25HIGH90MEDIUM141LOW16

Vulnerabilities

Page 11 of 14
CVE-2020-1935P4MEDIUMCVSS 4.8≥ 7.0.0, ≤ 7.0.99≥ 8.5.0, ≤ 8.5.50+2 more2020-02-24
CVE-2020-1935 [MEDIUM] CWE-444 CVE-2020-1935: In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing cod In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encodi
nvd
CVE-2012-2733P4MEDIUMCVSS 5.0v6.0v6.0.0+55 more2012-11-16
CVE-2012-2733 [MEDIUM] CWE-20 CVE-2012-2733: java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat java/org/apache/coyote/http11/InternalNioInputBuffer.java in the HTTP NIO connector in Apache Tomcat 6.x before 6.0.36 and 7.x before 7.0.28 does not properly restrict the request-header size, which allows remote attackers to cause a denial of service (memory consumption) via a large amount of header data.
nvd
CVE-2019-17569P4MEDIUMCVSS 4.8≥ 7.0.98, ≤ 7.0.99≥ 8.5.48, ≤ 8.5.50+1 more2020-02-24
CVE-2019-17569 [MEDIUM] CWE-444 CVE-2019-17569: The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 int The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the inval
nvd
CVE-2026-66299P4MEDIUMCVSS 5.3≥ 9.0.89, < 9.0.121≥ 10.1.24, < 10.1.58+8 more2026-07-28
CVE-2026-66299 [MEDIUM] CWE-400 CVE-2026-66299: Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This iss Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue. Users are recomm
nvd
CVE-2014-0099P4MEDIUMCVSS 4.3≤ 6.0.39v6+89 more2014-05-31
CVE-2014-0099 [MEDIUM] CWE-189 CVE-2014-0099: Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x b Integer overflow in java/org/apache/tomcat/util/buf/Ascii.java in Apache Tomcat before 6.0.40, 7.x before 7.0.53, and 8.x before 8.0.4, when operated behind a reverse proxy, allows remote attackers to conduct HTTP request smuggling attacks via a crafted Content-Length HTTP header.
nvd
CVE-2015-5174P4MEDIUMCVSS 4.3v6.0.0v6.0.1+80 more2016-02-25
CVE-2015-5174 [MEDIUM] CWE-22 CVE-2015-5174: Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before Directory traversal vulnerability in RequestUtil.java in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.65, and 8.x before 8.0.27 allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application in a getResource, getResourceAsStream, or getRe
nvd
CVE-2009-2902P4MEDIUMCVSS 4.3v5.5.0v5.5.1+49 more2010-01-28
CVE-2009-2902 [MEDIUM] CWE-22 CVE-2009-2902: Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 all Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to delete work-directory files via directory traversal sequences in a WAR filename, as demonstrated by the ...war filename.
nvd
CVE-2023-42795P4MEDIUMCVSS 5.3≥ 8.5.0, < 8.5.94≥ 9.0.1, < 9.0.81+4 more2023-10-10
CVE-2023-42795 [MEDIUM] CWE-459 CVE-2023-42795: Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the curren
nvd
CVE-2024-54677P4MEDIUMCVSS 5.3≥ 9.0.0, < 9.0.98≥ 10.1.0, < 10.1.34+1 more2024-12-17
CVE-2024-54677 [MEDIUM] CWE-400 CVE-2024-54677: Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following versions were EOL at the time the CVE was created but are known to be aff
nvd
CVE-2025-61795P4MEDIUMCVSS 5.3≥ 8.5.0, ≤ 8.5.100≥ 9.0.0, < 9.0.110+3 more2025-10-27
CVE-2025-61795 [MEDIUM] CWE-404 CVE-2025-61795: Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (includi Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memor
nvd
CVE-2026-32990P4MEDIUMCVSS 5.3≥ 9.0.113, < 9.0.116≥ 10.1.50, < 10.1.53+1 more2026-04-09
CVE-2026-32990 [MEDIUM] CWE-20 CVE-2026-32990: Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
nvd
CVE-2012-3544P4MEDIUMCVSS 5.0v6.0v6.0.0+57 more2013-06-01
CVE-2012-3544 [MEDIUM] CWE-20 CVE-2012-3544: Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in c Apache Tomcat 6.x before 6.0.37 and 7.x before 7.0.30 does not properly handle chunk extensions in chunked transfer coding, which allows remote attackers to cause a denial of service by streaming data.
nvd
CVE-2007-6286P4MEDIUMCVSS 4.3v5.5.11v5.5.12+29 more2008-02-12
CVE-2007-6286 [MEDIUM] CVE-2007-6286: Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, Apache Tomcat 5.5.11 through 5.5.25 and 6.0.0 through 6.0.15, when the native APR connector is used, does not properly handle an empty request to the SSL port, which allows remote attackers to trigger handling of "a duplicate copy of one of the recent requests," as demonstrated by using netcat to send the empty request.
nvd
CVE-2014-0095P4MEDIUMCVSS 5.0v8.0.0v8.0.1+1 more2014-05-31
CVE-2014-0095 [MEDIUM] CWE-20 CVE-2014-0095: java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote java/org/apache/coyote/ajp/AbstractAjpProcessor.java in Apache Tomcat 8.x before 8.0.4 allows remote attackers to cause a denial of service (thread consumption) by using a "Content-Length: 0" AJP request to trigger a hang in request processing.
nvd
CVE-2011-0534P4MEDIUMCVSS 5.0v7.0.0v7.0.1+32 more2011-02-10
CVE-2011-0534 [MEDIUM] CWE-399 CVE-2011-0534: Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize li Apache Tomcat 7.0.0 through 7.0.6 and 6.0.0 through 6.0.30 does not enforce the maxHttpHeaderSize limit for requests involving the NIO HTTP connector, which allows remote attackers to cause a denial of service (OutOfMemoryError) via a crafted request.
nvd
CVE-2013-4590P4MEDIUMCVSS 4.3v8.0.0≤ 6.0.37+172 more2014-02-26
CVE-2013-4590 [MEDIUM] CWE-200 CVE-2013-4590: Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain Apache Tomcat before 6.0.39, 7.x before 7.0.50, and 8.x before 8.0.0-RC10 allows attackers to obtain "Tomcat internals" information by leveraging the presence of an untrusted web application with a context.xml, web.xml, *.jspx, *.tagx, or *.tld XML document containing an external entity declaration in conjunction with an entity reference, related to a
nvd
CVE-2005-4836P4HIGHCVSS 7.8v4.1.15v4.1.16+23 more2005-12-31
CVE-2005-4836 [HIGH] CWE-200 CVE-2005-4836: The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL wh The HTTP/1.1 connector in Apache Tomcat 4.1.15 through 4.1.40 does not reject NULL bytes in a URL when allowLinking is configured, which allows remote attackers to read JSP source files and obtain sensitive information.
nvd
CVE-2011-1582P4MEDIUMCVSS 4.3v7.0.12v7.0.132011-05-20
CVE-2011-1582 [MEDIUM] CVE-2011-1582: Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security Apache Tomcat 7.0.12 and 7.0.13 processes the first request to a servlet without following security constraints that have been configured through annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088, CVE-2011-1183, and CVE-2011-1419.
nvd
CVE-2023-42794P4MEDIUMCVSS 5.9≥ 8.5.85, < 8.5.94≥ 9.0.70, < 9.0.812023-10-10
CVE-2023-42794 [MEDIUM] CWE-459 CVE-2023-42794: Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased, in progress refactoring that exposed a potential denial of service on Windows if a web application opened a stream for an uploaded file but failed to close the
nvd
CVE-2000-0672P4MEDIUMCVSS 5.0v3.0v3.12000-07-20
CVE-2000-0672 [MEDIUM] CVE-2000-0672: The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which al The default configuration of Jakarta Tomcat does not restrict access to the /admin context, which allows remote attackers to read arbitrary files by directly calling the administrative servlets to add a context for the root directory.
nvd