cbcvebase.

Apache Tomcat vulnerabilities

261 known vulnerabilities affecting apache/tomcat.

Total CVEs
261
CISA KEV
6
actively exploited
Public exploits
55
Exploited in wild
8
Severity breakdown
CRITICAL21HIGH85MEDIUM139LOW16

Vulnerabilities

Page 4 of 14
CVE-2026-53434P2CRITICALCVSS 9.1≥ 9.0.83, < 9.0.119≥ 10.1.0, < 10.1.56+1 more2026-06-29
CVE-2026-53434 [CRITICAL] CWE-390 CVE-2026-53434: Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.
nvd
CVE-2026-59083P2CRITICALCVSS 9.1≤ 8.0.0≥ 8.5.0, ≤ 8.5.100+3 more2026-07-14
CVE-2026-59083 [CRITICAL] CWE-177 CVE-2026-59083: Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allo Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached en
nvd
CVE-2010-4172P4MEDIUMCVSS 4.3PoCv6.0.12v6.0.13+17 more2010-11-26
CVE-2010-4172 [MEDIUM] CWE-79 CVE-2010-4172: Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0. Multiple cross-site scripting (XSS) vulnerabilities in the Manager application in Apache Tomcat 6.0.12 through 6.0.29 and 7.0.0 through 7.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) orderBy or (2) sort parameter to sessionsList.jsp, or unspecified input to (3) sessionDetail.jsp or (4) java/org/apache/catalina/manager/J
nvd
CVE-2007-3386P4MEDIUMCVSS 4.3PoCv5.5.0v5.5.1+37 more2007-08-14
CVE-2007-3386 [MEDIUM] CWE-79 CVE-2007-3386: Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0. Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.24 allows remote attackers to inject arbitrary HTML and web script via crafted requests, as demonstrated using the aliases parameter to an html/add action.
nvd
CVE-2024-24549P3HIGHCVSS 7.5≥ 8.5.0, < 8.5.99≥ 9.0.0, < 9.0.86+2 more2024-03-13
CVE-2024-24549 [HIGH] CWE-20 CVE-2024-24549: Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomca Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through
nvd
CVE-2007-1355P4MEDIUMCVSS 4.3PoCv4.0.0v4.0.1+50 more2007-05-21
CVE-2007-1355 [MEDIUM] CVE-2007-1355: Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example appli Multiple cross-site scripting (XSS) vulnerabilities in the appdev/sample/web/hello.jsp example application in Tomcat 4.0.0 through 4.0.6, 4.1.0 through 4.1.36, 5.0.0 through 5.0.30, 5.5.0 through 5.5.23, and 6.0.0 through 6.0.10 allow remote attackers to inject arbitrary web script or HTML via the test parameter and unspecified vectors.
nvd
CVE-2021-25122P3HIGHCVSS 7.5≥ 8.5.0, ≤ 8.5.61≥ 9.0.0, ≤ 9.0.41+2 more2021-03-01
CVE-2021-25122 [HIGH] CWE-200 CVE-2021-25122: When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
nvd
CVE-2015-5351P3HIGHCVSS 8.8v7.0.0v7.0.2+63 more2016-02-25
CVE-2015-5351 [HIGH] CWE-352 CVE-2015-5351: The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0 The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a CSRF protection mechanism by using a token.
nvd
CVE-2018-8034P3HIGHCVSS 7.5≥ 7.0.35, ≤ 7.0.88≥ 8.0.0, ≤ 8.0.52+39 more2018-08-01
CVE-2018-8034 [HIGH] CWE-295 CVE-2018-8034: The host name verification when using TLS with the WebSocket client was missing. It is now enabled b The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.
nvd
CVE-2020-17527P3HIGHCVSS 7.5≥ 8.5.1, ≤ 8.5.59≥ 9.0.1, ≤ 9.0.35+8 more2020-12-03
CVE-2020-17527 [HIGH] CWE-200 CVE-2020-17527: While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the
nvd
CVE-2026-55957P3HIGHCVSS 7.3fixed in 9.0.101≥ 10.1.0, < 10.1.37+1 more2026-06-29
CVE-2026-55957 [HIGH] CWE-304 CVE-2026-55957: Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was config Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0
nvd
CVE-2017-5647P3HIGHCVSS 7.5v6.0.0v6.0.1+185 more2017-04-17
CVE-2017-5647 [HIGH] CWE-200 CVE-2017-5647: A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5 A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined request being lost when send file processing of the previous request completed. This could result in responses appearing to be sent for the w
nvd
CVE-2002-2007P4MEDIUMCVSS 5.0PoCv3.2.3v3.2.42002-12-31
CVE-2002-2007 [MEDIUM] CVE-2002-2007: The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensiti The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system information such as directory listings and web root path, via erroneous HTTP requests for Java Server Pages (JSP) in the (1) test/jsp, (2) samples/jsp and (3) examples/jsp directories, or the (4) test/realPath.jsp servlet, which leaks pathnames in err
nvd
CVE-2002-1148P3MEDIUMCVSS 5.0PoCv3.0v3.1+17 more2002-10-11
CVE-2002-1148 [MEDIUM] CVE-2002-1148: The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and ear The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote attackers to read source code for server files via a direct request to the servlet.
nvd
CVE-2025-49125P3HIGHCVSS 7.5≥ 9.0.0, < 9.0.106≥ 10.1.0, < 10.1.42+1 more2025-06-16
CVE-2025-49125 [HIGH] CWE-288 CVE-2025-49125: Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowin
nvd
CVE-2020-11996P3HIGHCVSS 7.5≥ 8.5.0, ≤ 8.5.55≥ 9.0.0, ≤ 9.0.35+2 more2020-06-26
CVE-2020-11996 [HIGH] CVE-2020-11996: A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0. A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
nvd
CVE-2015-5346P3HIGHCVSS 8.1v7.0.0v7.0.2+61 more2016-02-25
CVE-2015-5346 [HIGH] CVE-2015-5346: Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote attackers to hijack web sessions by leveraging use of a requestedSessionSSL field for an unintended request, related to Coyote
nvd
CVE-2013-6357P4MEDIUMCVSS 6.8PoC≤ 5.5.25v1.1.3+89 more2013-11-13
CVE-2013-6357 [MEDIUM] CWE-352 CVE-2013-6357: Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 a Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a /manager/html/undeploy?path= URI. NOTE: the vendor disputes the significance
nvd
CVE-2003-0042P4MEDIUMCVSS 5.0PoCv3.0v3.1+7 more2003-02-07
CVE-2003-0042 [MEDIUM] CVE-2003-0042: Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list d Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with an index.html or other file present, or obtain unprocessed source code for a JSP file, via a URL containing a null character.
nvd
CVE-2016-3092P3HIGHCVSS 7.5v9.0.0v8.0.0+74 more2016-07-04
CVE-2016-3092 [HIGH] CWE-20 CVE-2016-3092: The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x be The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
nvd