cbcvebase.

Apache Tomcat vulnerabilities

261 known vulnerabilities affecting apache/tomcat.

Total CVEs
261
CISA KEV
6
actively exploited
Public exploits
55
Exploited in wild
8
Severity breakdown
CRITICAL21HIGH85MEDIUM139LOW16

Vulnerabilities

Page 5 of 14
CVE-2022-25762P3HIGHCVSS 8.6≥ 8.5.0, < 8.5.76≥ 9.0.0, < 9.0.212022-05-13
CVE-2022-25762 [HIGH] CWE-404 CVE-2022-25762: If a web application sends a WebSocket message concurrently with the WebSocket connection closing wh If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to b
nvd
CVE-2019-17563P3HIGHCVSS 7.5≥ 7.0.0, ≤ 7.0.98≥ 8.5.0, ≤ 8.5.49+1 more2019-12-23
CVE-2019-17563 [HIGH] CWE-384 CVE-2019-17563: When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7 When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.
nvd
CVE-2007-3382P4MEDIUMCVSS 4.3PoCv3.3v3.3.1+82 more2007-08-14
CVE-2007-3382 [MEDIUM] CWE-200 CVE-2007-3382: Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 t Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes ("'") as delimiters in cookies, which might cause sensitive information such as session IDs to be leaked and allow remote attackers to conduct session hijacking attacks.
nvd
CVE-2002-1567P4MEDIUMCVSS 6.8PoCv4.1.02003-10-06
CVE-2002-1567 [MEDIUM] CVE-2002-1567: Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arb Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.
nvd
CVE-2017-5648P3CRITICALCVSS 9.1v7.0.0v7.0.1+129 more2017-04-17
CVE-2017-5648 [CRITICAL] CWE-668 CVE-2017-5648: While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tom While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to
nvd
CVE-2016-8745P3HIGHCVSS 7.5v7.0.0v7.0.1+121 more2017-08-10
CVE-2016-8745 [HIGH] CWE-388 CVE-2016-8745: A bug in the error handling of the send file code for the NIO HTTP connector in Apache Tomcat 9.0.0. A bug in the error handling of the send file code for the NIO HTTP connector in Apache Tomcat 9.0.0.M1 to 9.0.0.M13, 8.5.0 to 8.5.8, 8.0.0.RC1 to 8.0.39, 7.0.0 to 7.0.73 and 6.0.16 to 6.0.48 resulted in the current Processor object being added to the Processor cache multiple times. This in turn meant that the same Processor could be used for concurrent
nvd
CVE-2019-2684P3MEDIUMCVSS 5.9≥ 7.0.0, ≤ 7.0.97≥ 8.5.0, ≤ 8.5.47+2 more2019-04-23
CVE-2019-2684 [MEDIUM] CVE-2019-2684: Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supp Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful
nvd
CVE-2002-2272P4HIGHCVSS 7.8PoCv4.0.0v4.0.1+12 more2002-12-31
CVE-2002-2272 [HIGH] CWE-119 CVE-2002-2272: Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote att Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a denial of service (desynchronized communications) via an HTTP GET request with a Transfer-Encoding chunked field with invalid values.
nvd
CVE-2017-5651P3CRITICALCVSS 9.8v8.5.0v8.5.1+12 more2017-04-17
CVE-2017-5651 [CRITICAL] CVE-2017-5651: In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors i In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processing. If the send file processing completed quickly, it was possible for the Processor to be added to the processor cache twice. This could result in the same Processor being used for multiple requests which in tu
nvd
CVE-2026-24880P3HIGHCVSS 7.5≥ 9.0.0, < 9.0.116≥ 10.1.0, < 10.1.53+1 more2026-04-09
CVE-2026-24880 [HIGH] CWE-444 CVE-2026-24880: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Ap Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other, unsupported version
nvd
CVE-2013-4444P3MEDIUMCVSS 6.8≤ 7.0.39v7.0.0+33 more2014-09-12
CVE-2013-4444 [MEDIUM] CWE-94 CVE-2013-4444: Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations inv Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.
nvd
CVE-2017-5664P3HIGHCVSS 7.5v7.0.0v7.0.1+133 more2017-06-06
CVE-2017-5664 [HIGH] CWE-755 CVE-2017-5664: The error page mechanism of the Java Servlet Specification requires that, when an error occurs and a The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is configured for the error that occurred, the original request and response are forwarded to the error page. This means that the request is presented to the error page with the original HTTP method. If the error page is a static file, expect
nvd
CVE-2017-7675P3HIGHCVSS 7.5v8.5.0v8.5.1+15 more2017-08-11
CVE-2017-7675 [HIGH] CWE-22 CVE-2017-7675: The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a numb The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. It was therefore possible to bypass security constraints using a specially crafted URL.
nvd
CVE-2025-48989P3HIGHCVSS 7.5≥ 9.0.1, < 9.0.108≥ 10.0.0, < 10.1.44+2 more2025-08-13
CVE-2025-48989 [HIGH] CWE-404 CVE-2025-48989: Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the m Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected. Users are recommended to upgrade to one of versions 11.0
nvd
CVE-2018-1336P3HIGHCVSS 7.5≥ 7.0.28, ≤ 7.0.86≥ 8.0.0, ≤ 8.0.51+4 more2018-08-02
CVE-2018-1336 [HIGH] CWE-835 CVE-2018-1336: An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an in An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
nvd
CVE-2026-42498P3HIGHCVSS 7.3≥ 7.0.0, ≤ 7.0.109≥ 8.5.0, ≤ 8.5.100+3 more2026-05-12
CVE-2026-42498 [HIGH] CWE-200 CVE-2026-42498: Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerabi Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109. Users are recommended to upgrade to version
nvd
CVE-2002-2006P4MEDIUMCVSS 5.0PoCv3.0v3.1+12 more2002-12-31
CVE-2002-2006 [MEDIUM] CVE-2002-2006: The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attack The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.
nvd
CVE-2002-0682P4HIGHCVSS 7.5PoCv4.0.32002-07-23
CVE-2002-0682 [HIGH] CVE-2002-0682: Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.
nvd
CVE-2011-3190P3HIGHCVSS 7.5v7.0.0v7.0.1+82 more2011-08-31
CVE-2011-3190 [HIGH] CWE-264 CVE-2011-3190: Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.
nvd
CVE-2014-0230P3HIGHCVSS 7.8v6.0.0v6.0.1+93 more2015-06-07
CVE-2014-0230 [HIGH] CWE-399 CVE-2014-0230: Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle ca Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.
nvd