Apache Tomcat vulnerabilities
272 known vulnerabilities affecting apache/tomcat.
Total CVEs
272
CISA KEV
7
actively exploited
Public exploits
55
Exploited in wild
9
Severity breakdown
CRITICAL25HIGH90MEDIUM141LOW16
Vulnerabilities
Page 4 of 14
CVE-2021-33037P3MEDIUMCVSS 5.3≥ 8.5.0, ≤ 8.5.66≤ 9.0.46+1 more2021-07-12
CVE-2021-33037 [MEDIUM] CWE-444 CVE-2021-33037: Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse th
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only
nvd
CVE-2010-4172P3MEDIUMCVSS 4.3PoCv6.0.12v6.0.13+17 more2010-11-26
CVE-2010-4172 [MEDIUM] CWE-79 CVE-2010-4172: Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.
Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/J
nvd
CVE-2007-3386P4MEDIUMCVSS 4.3PoCv5.5.0v5.5.1+37 more2007-08-14
CVE-2007-3386 [MEDIUM] CWE-79 CVE-2007-3386: Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.
Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.
nvd
CVE-2026-65637P2CRITICALCVSS 9.8≥ 9.0.115, < 9.0.121≥ 10.1.53, < 10.1.58+1 more2026-08-25
CVE-2026-65637 [CRITICAL] CVE-2026-65637: Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990.
Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990.
This issue affects Apache Tomcat: from 11.0.20 through 11.0.24, from 10.1.53 through 10.1.57, from 9.0.115 through 9.0.120.
Users are recommended to upgrade to version 11.0.25, 10.1.58 or 9.0.121, which fix the issue.
nvd
CVE-2007-5461P3LOWCVSS 3.5PoCv4.0.0v4.0.1+42 more2007-10-15
CVE-2007-5461 [LOW] CWE-22 CVE-2007-5461: Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 thro
Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.0 through 6.0.14, under certain configurations, allows remote authenticated users to read arbitrary files via a WebDAV write request that specifies an entity with a SYSTEM tag.
nvd
CVE-2026-53434P2CRITICALCVSS 9.1≥ 9.0.83, < 9.0.119≥ 10.1.0, < 10.1.56+1 more2026-06-29
CVE-2026-53434 [CRITICAL] CWE-390 CVE-2026-53434: Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118.
Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.
nvd
CVE-2026-59083P2CRITICALCVSS 9.1≤ 8.0.0≥ 8.5.0, ≤ 8.5.100+3 more2026-07-14
CVE-2026-59083 [CRITICAL] CWE-177 CVE-2026-59083: Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allo
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached en
nvd
CVE-2007-1355P4MEDIUMCVSS 4.3PoCv4.0.0v4.0.1+50 more2007-05-21
CVE-2007-1355 [MEDIUM] CVE-2007-1355: Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example appli
Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web script or HTML via the test parameter and unspecified vectors.
nvd
CVE-2024-24549P3HIGHCVSS 7.5≥ 8.5.0, < 8.5.99≥ 9.0.0, < 9.0.86+2 more2024-03-13
CVE-2024-24549 [HIGH] CWE-20 CVE-2024-24549: Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomca
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through
nvd
CVE-2026-65182P2CRITICALCVSS 9.1≥ 7.0.0, ≤ 7.0.109≥ 8.5.0, < 9.0.121+2 more2026-08-25
CVE-2026-65182 [CRITICAL] CWE-284 CVE-2026-65182: Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security co
Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0
nvd
CVE-2015-5351P3HIGHCVSS 8.8v7.0.0v7.0.2+63 more2016-02-25
CVE-2015-5351 [HIGH] CWE-352 CVE-2015-5351: The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0
The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protection mechanism by using a token.
nvd
CVE-2021-25122P3HIGHCVSS 7.5≥ 8.5.0, ≤ 8.5.61≥ 9.0.0, ≤ 9.0.41+34 more2021-03-01
CVE-2021-25122 [HIGH] CWE-200 CVE-2021-25122: When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
nvd
CVE-2018-8034P3HIGHCVSS 7.5≥ 7.0.35, ≤ 7.0.88≥ 8.0.0, ≤ 8.0.52+39 more2018-08-01
CVE-2018-8034 [HIGH] CWE-295 CVE-2018-8034: The host name verification when using TLS with the WebSocket client was missing. It is now enabled b
The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.
nvd
CVE-2026-68569P3HIGHCVSS 8.1≥ 7.0.0, ≤ 7.0.109≥ 8.5.0, < 9.0.121+2 more2026-08-25
CVE-2026-68569 [HIGH] CWE-287 CVE-2026-68569: Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT
Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following v
nvd
CVE-2020-17527P3HIGHCVSS 7.5≥ 8.5.1, ≤ 8.5.59≥ 9.0.1, ≤ 9.0.35+8 more2020-12-03
CVE-2020-17527 [HIGH] CWE-200 CVE-2020-17527: While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the
nvd
CVE-2020-11996P3HIGHCVSS 7.5≥ 8.5.0, ≤ 8.5.55≥ 9.0.0, ≤ 9.0.35+2 more2020-06-26
CVE-2020-11996 [HIGH] CVE-2020-11996: A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
nvd
CVE-2026-55957P3HIGHCVSS 7.3fixed in 9.0.101≥ 10.1.0, < 10.1.37+1 more2026-06-29
CVE-2026-55957 [HIGH] CWE-304 CVE-2026-55957: Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was config
Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0
nvd
CVE-2002-1148P3MEDIUMCVSS 5.0PoCv3.0v3.1+17 more2002-10-11
CVE-2002-1148 [MEDIUM] CVE-2002-1148: The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and ear
The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.
nvd
CVE-2017-5647P3HIGHCVSS 7.5v6.0.0v6.0.1+185 more2017-04-17
CVE-2017-5647 [HIGH] CWE-200 CVE-2017-5647: A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5
A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined request being lost when send file processing of the previous request completed. This could result in responses appearing to be sent for the w
nvd
CVE-2002-2007P4MEDIUMCVSS 5.0PoCv3.2.3v3.2.42002-12-31
CVE-2002-2007 [MEDIUM] CVE-2002-2007: The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensiti
The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in err
nvd