cbcvebase.

Apache Tomcat vulnerabilities

261 known vulnerabilities affecting apache/tomcat.

Total CVEs
261
CISA KEV
6
actively exploited
Public exploits
55
Exploited in wild
8
Severity breakdown
CRITICAL21HIGH85MEDIUM139LOW16

Vulnerabilities

Page 2 of 14
CVE-2018-11784P3MEDIUMCVSS 4.3PoC≥ 7.0.23, ≤ 7.0.90≥ 8.5.0, ≤ 8.5.33+2 more2018-10-04
CVE-2018-11784 [MEDIUM] CWE-601 CVE-2018-11784: When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.
nvd
CVE-2025-55752P2HIGHCVSS 7.5≥ 8.5.6, ≤ 8.5.100≥ 9.0.1, < 9.0.109+4 more2025-10-27
CVE-2025-55752 [HIGH] CWE-23 CVE-2025-55752: Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regressi Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the pr
nvd
CVE-2010-2227P3MEDIUMCVSS 6.4PoCv5.5.0v5.5.1+53 more2010-07-13
CVE-2010-2227 [MEDIUM] CWE-119 CVE-2010-2227: Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."
nvd
CVE-2016-6816P3HIGHCVSS 7.1PoCv6.0.0v6.0.1+166 more2017-03-20
CVE-2016-6816 [HIGH] CWE-20 CVE-2016-6816: The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.7 The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP respons
nvd
CVE-2019-0221P3MEDIUMCVSS 6.1PoC≥ 7.0.0, ≤ 7.0.93≥ 8.5.0, ≤ 8.5.39+2 more2019-05-28
CVE-2019-0221 [MEDIUM] CWE-79 CVE-2019-0221: The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.
nvd
CVE-2011-4858P3MEDIUMCVSS 5.0PoCv5.5.35v6.0.0+57 more2012-01-05
CVE-2011-4858 [MEDIUM] CWE-399 CVE-2011-4858: Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without restricting the ability to trigger hash collisions predictably, which allows remote attackers to cause a denial of service (CPU consumption) by sending many crafted parameters.
nvd
CVE-2017-12616P2HIGHCVSS 7.5v7.0.0v7.0.1+76 more2017-09-19
CVE-2017-12616 [HIGH] CWE-200 CVE-2017-12616: When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.
nvd
CVE-2016-1240P3HIGHCVSS 7.8PoCv6.0v7.0+1 more2016-10-03
CVE-2016-1240 [HIGH] CWE-20 CVE-2016-1240: The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0. The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debian jessie and the tomcat6 and libtomcat6-java packages before 6.0.35-1ubuntu3.8 on Ubuntu 12.04 LTS, the tomcat7 and libtomcat7-java packages before 7.0.52-1ubuntu0.7 on Ubuntu 14.04 LTS, and tomcat8 and libtomcat8-java packages before 8
nvd
CVE-2009-0580P3MEDIUMCVSS 4.3PoCv4.1.0v4.1.1+83 more2009-06-05
CVE-2009-0580 [MEDIUM] CWE-200 CVE-2009-0580: Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authen Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, allows remote attackers to enumerate valid usernames via requests to /j_security_check with malformed URL encoding of passwords, related to improper error checking in the (1) MemoryRealm, (2) DataSourceRealm, and (3) JDBCRealm authenti
nvd
CVE-2008-2370P3MEDIUMCVSS 5.0PoCv4.1.0v4.1.1+80 more2008-08-04
CVE-2008-2370 [MEDIUM] CWE-22 CVE-2008-2370: Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDi Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, performs path normalization before removing the query string from the URI, which allows remote attackers to conduct directory traversal attacks and read arbitrary files via a .. (dot dot) in a request parameter.
nvd
CVE-2007-5333P3MEDIUMCVSS 5.0PoC≥ 4.1.0, ≤ 4.1.36≥ 5.5.0, ≤ 5.5.25+1 more2008-02-12
CVE-2007-5333 [MEDIUM] CVE-2007-5333: Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double quote (") characters or (2) %5C (encoded backslash) sequences in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks. NOTE: this issue exists becaus
nvd
CVE-2024-52316P2CRITICALCVSS 9.8≥ 9.0.0, < 9.0.96≥ 10.1.0, < 10.1.31+1 more2024-11-18
CVE-2024-52316 [CRITICAL] CWE-391 CVE-2024-52316: Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Ja Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to by
nvd
CVE-2025-48988P2HIGHCVSS 7.5≥ 9.0.0, < 9.0.106≥ 10.1.0, < 10.1.42+1 more2025-06-16
CVE-2025-48988 [HIGH] CWE-770 CVE-2025-48988: Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue aff Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versio
nvd
CVE-2019-0199P3HIGHCVSS 7.5≥ 8.5.0, ≤ 8.5.37≥ 9.0.1, ≤ 9.0.14+1 more2019-04-10
CVE-2019-0199 [HIGH] CWE-400 CVE-2019-0199: The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams w The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request/response data. By keeping streams open for requests that utilised the Servlet API's blocking I/O, clients were able to cause server-si
nvd
CVE-2016-5388P2HIGHCVSS 8.1≥ 6.0, ≤ 6.0.45≥ 7.0, ≤ 7.0.70+1 more2016-07-19
CVE-2016-5388 [HIGH] CWE-284 CVE-2016-5388: Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an application's outbound HTTP traffic to an arbitrary proxy
nvd
CVE-2019-10072P3HIGHCVSS 7.5≥ 8.5.0, ≤ 8.5.40≥ 9.0.1, ≤ 9.0.19+1 more2019-06-21
CVE-2019-10072 [HIGH] CVE-2019-10072: The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDATE messages for the connection window (stream 0) clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
nvd
CVE-2026-41293P2CRITICALCVSS 9.8≥ 8.5.0, ≤ 8.5.100≥ 9.0.0, < 9.0.118+3 more2026-05-12
CVE-2026-41293 [CRITICAL] CWE-20 CVE-2026-41293: Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11 Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the
nvd
CVE-2026-50229P3MEDIUMCVSS 6.1PoC≤ 7.0.109≥ 8.5.0, ≤ 8.5.100+3 more2026-06-29
CVE-2026-50229 [MEDIUM] CWE-80 CVE-2026-50229: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the n Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have re
nvd
CVE-2025-55754P2CRITICALCVSS 9.6≥ 8.5.60, ≤ 8.5.100≥ 9.0.40, < 9.0.109+3 more2025-10-27
CVE-2025-55754 [CRITICAL] CWE-150 CVE-2025-55754: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomca Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI e
nvd
CVE-2024-56337P2CRITICALCVSS 9.8≥ 9.0.0, < 9.0.98≥ 10.1.0, < 10.1.34+1 more2024-12-20
CVE-2024-56337 [CRITICAL] CVE-2024-56337: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affect Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.0.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may a
nvd
Apache Tomcat vulnerabilities | cvebase