Apache Tomcat vulnerabilities
272 known vulnerabilities affecting apache/tomcat.
Total CVEs
272
CISA KEV
7
actively exploited
Public exploits
55
Exploited in wild
9
Severity breakdown
CRITICAL25HIGH90MEDIUM141LOW16
Vulnerabilities
Page 6 of 14
CVE-2026-65183P3HIGHCVSS 8.1≥ 9.0.42, < 9.0.121≥ 10.1.0, < 10.1.58+1 more2026-08-25
CVE-2026-65183 [HIGH] CWE-367 CVE-2026-65183: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120.
Users are recommended to upgrade to vers
nvd
CVE-2002-0682P4HIGHCVSS 7.5PoCv4.0.32002-07-23
CVE-2002-0682 [HIGH] CVE-2002-0682: Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script
Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users via script in a URL with the /servlet/ mapping, which does not filter the script when an exception is thrown by the servlet.
nvd
CVE-2026-42498P3HIGHCVSS 7.3≥ 7.0.0, ≤ 7.0.109≥ 8.5.0, ≤ 8.5.100+3 more2026-05-12
CVE-2026-42498 [HIGH] CWE-200 CVE-2026-42498: Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerabi
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109.
Users are recommended to upgrade to version
nvd
CVE-2002-2006P4MEDIUMCVSS 5.0PoCv3.0v3.1+12 more2002-12-31
CVE-2002-2006 [MEDIUM] CVE-2002-2006: The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attack
The default installation of Apache Tomcat 4.0 through 4.1 and 3.0 through 3.3.1 allows remote attackers to obtain the installation path and other sensitive system information via the (1) SnoopServlet or (2) TroubleShooter example servlets.
nvd
CVE-2025-48989P3HIGHCVSS 7.5≥ 9.0.1, < 9.0.108≥ 10.0.0, < 10.1.44+2 more2025-08-13
CVE-2025-48989 [HIGH] CWE-404 CVE-2025-48989: Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the m
Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected.
Users are recommended to upgrade to one of versions 11.0
nvd
CVE-2011-3190P3HIGHCVSS 7.5v7.0.0v7.0.1+82 more2011-08-31
CVE-2011-3190 [HIGH] CWE-264 CVE-2011-3190: Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through
Certain AJP protocol connector implementations in Apache Tomcat 7.0.0 through 7.0.20, 6.0.0 through 6.0.33, 5.5.0 through 5.5.33, and possibly other versions allow remote attackers to spoof AJP requests, bypass authentication, and obtain sensitive information by causing the connector to interpret a request body as a new request.
nvd
CVE-2014-0230P3HIGHCVSS 7.8v6.0.0v6.0.1+93 more2015-06-07
CVE-2014-0230 [HIGH] CWE-399 CVE-2014-0230: Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle ca
Apache Tomcat 6.x before 6.0.44, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle cases where an HTTP response occurs before finishing the reading of an entire request body, which allows remote attackers to cause a denial of service (thread consumption) via a series of aborted upload attempts.
nvd
CVE-2025-46701P3HIGHCVSS 7.3≥ 9.0.0, < 9.0.105≥ 10.1.0, < 10.1.41+1 more2025-05-29
CVE-2025-46701 [HIGH] CWE-178 CVE-2025-46701: Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security c
Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104.
The follow
nvd
CVE-2007-3385P4MEDIUMCVSS 4.3PoCv3.3v3.3.1+82 more2007-08-14
CVE-2007-3385 [MEDIUM] CWE-200 CVE-2007-3385: Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 d
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.
nvd
CVE-2026-43513P3HIGHCVSS 7.5≥ 7.0.0, ≤ 7.0.109≥ 8.5.0, ≤ 8.5.100+3 more2026-05-12
CVE-2026-43513 [HIGH] CWE-178 CVE-2026-43513: Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue af
Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Older unsupported versions may also be affected.
Users are recommended to upgrade
nvd
CVE-2026-53404P3HIGHCVSS 7.3≥ 8.5.0, ≤ 8.5.100≥ 9.0.0, < 9.0.119+2 more2026-06-29
CVE-2026-53404 [HIGH] CWE-670 CVE-2026-53404: Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant th
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Ot
nvd
CVE-2003-0866P4MEDIUMCVSS 5.0PoCv4.0.0v4.0.1+5 more2003-11-17
CVE-2003-0866 [MEDIUM] CVE-2003-0866: The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote at
The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.
nvd
CVE-2002-0936P4MEDIUMCVSS 5.0PoCv4.0.32002-10-04
CVE-2002-0936 [MEDIUM] CVE-2002-0936: The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (en
The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).
nvd
CVE-2021-24122P3MEDIUMCVSS 5.9≥ 7.0.0, ≤ 7.0.106≥ 8.5.0, ≤ 8.5.59+37 more2021-01-14
CVE-2021-24122 [MEDIUM] CWE-200 CVE-2021-24122: When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root cause was the unexpected behaviour of the JRE API File.getCanonicalPath() which in turn was
nvd
CVE-2026-41284P3HIGHCVSS 7.5≥ 4.0.0, ≤ 7.0.109≥ 8.5.0, ≤ 8.5.100+4 more2026-05-12
CVE-2026-41284 [HIGH] CWE-770 CVE-2026-41284: Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue aff
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117.
Older, unsupported versions may also be affected.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
nvd
CVE-2026-34483P3HIGHCVSS 7.5≥ 9.0.40, < 9.0.117≥ 10.1.0, < 10.1.54+1 more2026-04-09
CVE-2026-34483 [HIGH] CWE-116 CVE-2026-34483: Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache
Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.
nvd
CVE-2024-34750P3HIGHCVSS 7.5≥ 9.0.0, < 9.0.90≥ 10.1.0, < 10.1.25+1 more2024-07-03
CVE-2024-34750 [HIGH] CWE-400 CVE-2024-34750: Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apac
Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections
nvd
CVE-2023-46589P3HIGHCVSS 7.5≥ 8.5.0, < 8.5.96≥ 9.0.0, < 9.0.83+2 more2023-11-28
CVE-2023-46589 [HIGH] CWE-444 CVE-2023-46589: Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, f
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single
request as multiple request
nvd
CVE-2016-6796P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.0.45≥ 7.0.0, ≤ 7.0.70+3 more2017-08-11
CVE-2016-6796 [HIGH] CVE-2016-6796: A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1
A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.
nvd
CVE-2016-6797P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.0.45≥ 7.0.0, ≤ 7.0.70+3 more2017-08-10
CVE-2016-6797 [HIGH] CWE-863 CVE-2016-6797: The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resour
nvd