Apache Tomcat vulnerabilities
261 known vulnerabilities affecting apache/tomcat.
Total CVEs
261
CISA KEV
6
actively exploited
Public exploits
55
Exploited in wild
8
Severity breakdown
CRITICAL21HIGH85MEDIUM139LOW16
Vulnerabilities
Page 3 of 14
CVE-2026-43512P2CRITICALCVSS 9.8≥ 7.0.0, ≤ 7.0.109≥ 8.5.0, ≤ 8.5.100+3 more2026-05-12
CVE-2026-43512 [CRITICAL] CWE-592 CVE-2026-43512: DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. T
DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0.
Older unsupported versions any also be affect
Users are recommended to upg
nvd
CVE-2007-2449P4MEDIUMCVSS 4.3PoC≤ 4.1.36v4.0.0+71 more2007-06-14
CVE-2007-2449 [MEDIUM] CVE-2007-2449: Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web applica
Multiple cross-site scripting (XSS) vulnerabilities in certain JSP files in the examples web application in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.24, and 6.0.0 through 6.0.13 allow remote attackers to inject arbitrary web script or HTML via the portion of the URI after the ';' character, as demonstrat
nvd
CVE-2025-31651P2CRITICALCVSS 9.8≥ 9.0.0, < 9.0.104≥ 10.1.0, < 10.1.40+1 more2025-04-28
CVE-2025-31651 [CRITICAL] CWE-116 CVE-2025-31651: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible
for a specially crafted request to bypass some rewrite rules. If those
rewrite rules effectively enforced security constraints, those
constraints could be bypassed.
This issue affects A
nvd
CVE-2023-28709P3HIGHCVSS 7.5≥ 8.5.85, ≤ 8.5.87≥ 9.0.71, ≤ 9.0.73+2 more2023-05-22
CVE-2023-28709 [HIGH] CVE-2023-28709: The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7
The fix for CVE-2023-24998 was incomplete for Apache Tomcat 11.0.0-M2 to 11.0.0-M4, 10.1.5 to 10.1.7, 9.0.71 to 9.0.73 and 8.5.85 to 8.5.87. If non-default HTTP connector settings were used such that the maxParameterCount could be reached using query string parameters and a request was submitted that supplied exactly maxParameterCount parameters in the query
nvd
CVE-2000-0760P4MEDIUMCVSS 6.4PoCv3.0v3.12000-10-20
CVE-2000-0760 [MEDIUM] CVE-2000-0760: The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information wh
The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.
nvd
CVE-2025-66614P2CRITICALCVSS 9.1≥ 9.0.1, < 9.0.113≥ 10.1.1, < 10.1.50+4 more2026-02-17
CVE-2025-66614 [CRITICAL] CWE-20 CVE-2025-66614: Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 1
Improper Input Validation vulnerability.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected.
Tomcat did not validate t
nvd
CVE-2020-13934P3HIGHCVSS 7.5≥ 8.5.1, ≤ 8.5.56≥ 9.0.1, ≤ 9.0.36+2 more2020-07-14
CVE-2020-13934 [HIGH] CWE-401 CVE-2020-13934: An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.
nvd
CVE-2006-7196P4MEDIUMCVSS 4.3PoC≤ 4.1.31v4.0.0+52 more2007-05-10
CVE-2006-7196 [MEDIUM] CVE-2006-7196: Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0
Cross-site scripting (XSS) vulnerability in the calendar application example in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.31, 5.0.0 through 5.0.30, and 5.5.0 through 5.5.15 allows remote attackers to inject arbitrary web script or HTML via the time parameter to cal2.jsp and possibly unspecified other vectors. NOTE: this may be related to CVE-2006-02
nvd
CVE-2008-1232P4MEDIUMCVSS 4.3PoC≥ 4.1.0, ≤ 4.1.37≥ 5.5.0, ≤ 5.5.26+1 more2008-08-04
CVE-2008-1232 [MEDIUM] CWE-79 CVE-2008-1232: Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26
Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16 allows remote attackers to inject arbitrary web script or HTML via a crafted string that is used in the message argument to the HttpServletResponse.sendError method.
nvd
CVE-2023-45648P3MEDIUMCVSS 5.3PoC≥ 8.5.0, < 8.5.94≥ 9.0.1, < 9.0.81+4 more2023-10-10
CVE-2023-45648 [MEDIUM] CWE-20 CVE-2023-45648: Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, f
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially
crafted, invalid trailer header could cause Tomcat to treat a single
request as multiple requests leadin
nvd
CVE-2026-55276P2CRITICALCVSS 9.1fixed in 9.0.119≥ 10.1.0, < 10.1.56+1 more2026-06-29
CVE-2026-55276 [CRITICAL] CWE-670 CVE-2026-55276: Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.10
nvd
CVE-2006-3835P3MEDIUMCVSS 5.0PoCv5.0.28v5.5.7+3 more2006-07-25
CVE-2006-3835 [MEDIUM] CVE-2006-3835: Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preced
Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preceding a filename with a mapped extension, as demonstrated by URLs ending with /;index.jsp and /;help.do.
nvd
CVE-2026-43515P2CRITICALCVSS 9.1≥ 7.0.0, ≤ 7.0.109≥ 8.5.0, ≤ 8.5.100+3 more2026-05-12
CVE-2026-43515 [CRITICAL] CWE-285 CVE-2026-43515: Improper Authorization vulnerability when multiple method constraints define an HTTP method for the
Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgra
nvd
CVE-2026-29145P2CRITICALCVSS 9.1≥ 9.0.83, < 9.0.116≥ 10.1.1, < 10.1.53+2 more2026-04-09
CVE-2026-29145 [CRITICAL] CWE-287 CVE-2026-29145: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled v
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through
nvd
CVE-2026-59084P2CRITICALCVSS 9.1≥ 7.0.100, ≤ 7.0.109≥ 8.5.38, ≤ 8.5.100+3 more2026-07-14
CVE-2026-59084 [CRITICAL] CWE-1059 CVE-2026-59084: Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to secure
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.1
nvd
CVE-2018-8014P2CRITICALCVSS 9.8≥ 7.0.41, ≤ 7.0.88≥ 8.0.0, ≤ 8.0.52+4 more2018-05-16
CVE-2018-8014 [CRITICAL] CWE-1188 CVE-2018-8014: The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default conf
nvd
CVE-2010-1157P3LOWCVSS 2.6PoCv5.5.0v5.5.1+51 more2010-04-23
CVE-2010-1157 [LOW] CWE-200 CVE-2010-1157: Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover
Apache Tomcat 5.5.0 through 5.5.29 and 6.0.0 through 6.0.26 might allow remote attackers to discover the server's hostname or IP address by sending a request for a resource that requires (1) BASIC or (2) DIGEST authentication, and then reading the realm field in the WWW-Authenticate header in the reply.
nvd
CVE-2007-5461P3LOWCVSS 3.5PoCv4.0.0v4.0.1+42 more2007-10-15
CVE-2007-5461 [LOW] CWE-22 CVE-2007-5461: Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 thro
Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.
nvd
CVE-2016-0714P3HIGHCVSS 8.8v6.0.0v6.0.1+88 more2016-02-25
CVE-2016-0714 [HIGH] CWE-264 CVE-2016-0714: The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x be
The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass intended SecurityManager restrictions and execute arbitrary code in a privileged context via a web application that places a crafted obje
nvd
CVE-2021-33037P3MEDIUMCVSS 5.3≥ 8.5.0, ≤ 8.5.66≤ 9.0.46+1 more2021-07-12
CVE-2021-33037 [MEDIUM] CWE-444 CVE-2021-33037: Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse th
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only
nvd