Apache Tomcat vulnerabilities
261 known vulnerabilities affecting apache/tomcat.
Total CVEs
261
CISA KEV
6
actively exploited
Public exploits
55
Exploited in wild
8
Severity breakdown
CRITICAL21HIGH85MEDIUM139LOW16
Vulnerabilities
Page 6 of 14
CVE-2025-46701P3HIGHCVSS 7.3≥ 9.0.0, < 9.0.105≥ 10.1.0, < 10.1.41+1 more2025-05-29
CVE-2025-46701 [HIGH] CWE-178 CVE-2025-46701: Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security c
Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104.
The follow
nvd
CVE-2007-3385P4MEDIUMCVSS 4.3PoCv3.3v3.3.1+82 more2007-08-14
CVE-2007-3385 [MEDIUM] CWE-200 CVE-2007-3385: Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 d
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 does not properly handle the \" character sequence in a cookie value, which might cause sensitive information such as session IDs to be leaked to remote attackers and enable session hijacking attacks.
nvd
CVE-2003-0866P4MEDIUMCVSS 5.0PoCv4.0.0v4.0.1+5 more2003-11-17
CVE-2003-0866 [MEDIUM] CVE-2003-0866: The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote at
The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a denial of service via several requests that do not follow the HTTP protocol, which causes Tomcat to reject later requests.
nvd
CVE-2026-43513P3HIGHCVSS 7.5≥ 7.0.0, ≤ 7.0.109≥ 8.5.0, ≤ 8.5.100+3 more2026-05-12
CVE-2026-43513 [HIGH] CWE-178 CVE-2026-43513: Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue af
Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Older unsupported versions may also be affected.
Users are recommended to upgrade
nvd
CVE-2026-53404P3HIGHCVSS 7.3≥ 8.5.0, ≤ 8.5.100≥ 9.0.0, < 9.0.119+2 more2026-06-29
CVE-2026-53404 [HIGH] CWE-670 CVE-2026-53404: Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant th
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Ot
nvd
CVE-2002-0936P4MEDIUMCVSS 5.0PoCv4.0.32002-10-04
CVE-2002-0936 [MEDIUM] CVE-2002-0936: The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (en
The Java Server Pages (JSP) engine in Tomcat allows web page owners to cause a denial of service (engine crash) on the web server via a JSP page that calls WPrinterJob().pageSetup(null,null).
nvd
CVE-2021-24122P3MEDIUMCVSS 5.9≥ 7.0.0, ≤ 7.0.106≥ 8.5.0, ≤ 8.5.59+3 more2021-01-14
CVE-2021-24122 [MEDIUM] CWE-200 CVE-2021-24122: When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root cause was the unexpected behaviour of the JRE API File.getCanonicalPath() which in turn was
nvd
CVE-2026-34483P3HIGHCVSS 7.5≥ 9.0.40, < 9.0.117≥ 10.1.0, < 10.1.54+1 more2026-04-09
CVE-2026-34483 [HIGH] CWE-116 CVE-2026-34483: Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache
Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.
nvd
CVE-2024-34750P3HIGHCVSS 7.5≥ 9.0.0, < 9.0.90≥ 10.1.0, < 10.1.25+1 more2024-07-03
CVE-2024-34750 [HIGH] CWE-400 CVE-2024-34750: Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apac
Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections
nvd
CVE-2023-46589P3HIGHCVSS 7.5≥ 8.5.0, < 8.5.96≥ 9.0.0, < 9.0.83+2 more2023-11-28
CVE-2023-46589 [HIGH] CWE-444 CVE-2023-46589: Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, f
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single
request as multiple request
nvd
CVE-2016-6796P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.0.45≥ 7.0.0, ≤ 7.0.70+3 more2017-08-11
CVE-2016-6796 [HIGH] CVE-2016-6796: A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1
A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.
nvd
CVE-2025-53506P3HIGHCVSS 7.5≥ 9.0.0, ≤ 9.0.106≥ 10.1.0, ≤ 10.1.42+1 more2025-07-10
CVE-2025-53506 [HIGH] CWE-400 CVE-2025-53506: Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowl
Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.
The following versions were EOL at th
nvd
CVE-2026-41284P3HIGHCVSS 7.5≥ 4.0.0, ≤ 7.0.109≥ 8.5.0, ≤ 8.5.100+4 more2026-05-12
CVE-2026-41284 [HIGH] CWE-770 CVE-2026-41284: Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue aff
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117.
Older, unsupported versions may also be affected.
Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
nvd
CVE-2001-0590P4MEDIUMCVSS 5.0PoC≤ 3.2.22001-08-02
CVE-2001-0590 [MEDIUM] CVE-2001-0590: Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source
Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).
nvd
CVE-2016-6797P3HIGHCVSS 7.5≥ 6.0.0, ≤ 6.0.45≥ 7.0.0, ≤ 7.0.70+3 more2017-08-10
CVE-2016-6797 [HIGH] CWE-863 CVE-2016-6797: The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resour
nvd
CVE-2025-52520P3HIGHCVSS 7.5≥ 9.0.0, < 9.0.107≥ 10.1.0, < 10.1.43+1 more2025-07-10
CVE-2025-52520 [HIGH] CWE-190 CVE-2025-52520: For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache To
For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.
The following versions were EOL at the time the CVE was created but a
nvd
CVE-2021-30640P3MEDIUMCVSS 6.5≥ 7.0.0, < 7.0.109≥ 8.5.0, < 8.5.66+2 more2021-07-12
CVE-2021-30640 [MEDIUM] CWE-116 CVE-2021-30640: A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variatio
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
nvd
CVE-2020-13943P3MEDIUMCVSS 4.3v8.5.0v8.5.1+95 more2020-10-12
CVE-2020-13943 [MEDIUM] CVE-2020-13943: If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0
If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a p
nvd
CVE-2026-24734P3HIGHCVSS 7.5≥ 9.0.83, < 9.0.115≥ 10.1.1, < 10.1.52+47 more2026-02-17
CVE-2026-24734 [HIGH] CWE-20 CVE-2026-24734: Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat.
When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed.
This issue affects Apache Tomcat Native: from 1.3.0
nvd
CVE-2026-29129P3HIGHCVSS 7.5≥ 9.0.114, < 9.0.116≥ 10.1.51, < 10.1.53+1 more2026-04-09
CVE-2026-29129 [HIGH] CWE-327 CVE-2026-29129: Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects
Configured cipher preference order not preserved vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
nvd