Apache Tomcat vulnerabilities
261 known vulnerabilities affecting apache/tomcat.
Total CVEs
261
CISA KEV
6
actively exploited
Public exploits
55
Exploited in wild
8
Severity breakdown
CRITICAL21HIGH85MEDIUM139LOW16
Vulnerabilities
Page 7 of 14
CVE-2025-52434P3HIGHCVSS 7.5≥ 9.0.0, < 9.0.1072025-07-10
CVE-2025-52434 [HIGH] CWE-362 CVE-2025-52434: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerab
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.
This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106.
The following versions were EOL at the tim
nvd
CVE-2016-8747P3HIGHCVSS 7.5≥ 8.5.7, < 8.5.10v9.0.02017-03-14
CVE-2016-8747 [HIGH] CWE-200 CVE-2016-8747: An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.
An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request.
nvd
CVE-2021-30639P3HIGHCVSS 7.5v8.5.64v9.0.44+2 more2021-07-12
CVE-2021-30639 [HIGH] CWE-755 CVE-2021-30639: A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An erro
A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the Request object was not reset between requests. This meant that once a non-blocking I/O error occurred, all future requests h
nvd
CVE-2026-34487P3HIGHCVSS 7.5≥ 9.0.13, < 9.0.117≥ 10.1.0, < 10.1.54+1 more2026-04-09
CVE-2026-34487 [HIGH] CWE-532 CVE-2026-34487: Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clusterin
Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.
nvd
CVE-2021-42340P3HIGHCVSS 7.5≥ 8.5.60, < 8.5.72≥ 9.0.40, < 9.0.54+3 more2021-10-14
CVE-2021-42340 [HIGH] CWE-772 CVE-2021-42340: The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could le
nvd
CVE-2025-49124P3HIGHCVSS 8.4≥ 9.0.23, < 9.0.106≥ 10.1.0, < 10.1.42+1 more2025-06-16
CVE-2025-49124 [HIGH] CWE-426 CVE-2025-49124: Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the
Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105.
The following versions were EOL at the time the CVE
nvd
CVE-2017-5650P3HIGHCVSS 7.5v8.5.0v8.5.1+12 more2017-04-17
CVE-2017-5650 [HIGH] CWE-404 CVE-2017-5650: In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame f
In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated with that connection that were currently waiting for a WINDOW_UPDATE before allowing the application to write more data. These waiting streams each consumed a thread. A malicious client could therefore cons
nvd
CVE-2024-38286P3HIGHCVSS 7.5≥ 9.0.13, < 9.0.90≥ 10.1.1, < 10.1.25+2 more2024-11-07
CVE-2024-38286 [HIGH] CWE-770 CVE-2024-38286: Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue aff
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7
nvd
CVE-2018-1304P3MEDIUMCVSS 5.9≥ 7.0.0, ≤ 7.0.84≥ 8.0.0, ≤ 8.0.49+4 more2018-02-28
CVE-2018-1304 [MEDIUM] CVE-2018-1304: The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly ha
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access
nvd
CVE-2021-41079P3HIGHCVSS 7.5≥ 8.5.0, < 8.5.64≥ 9.0.0, < 9.0.44+1 more2021-09-16
CVE-2021-41079 [HIGH] CWE-20 CVE-2021-41079: Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.
nvd
CVE-2005-4703P4MEDIUMCVSS 5.0PoCv4.0.32005-12-31
CVE-2005-4703 [MEDIUM] CVE-2005-4703: Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive informatio
Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DOS device name such as lpt9, which leaks the pathname in an error message, as demonstrated by lpt9.xtp using Nikto.
nvd
CVE-2014-0227P3MEDIUMCVSS 6.4v6.0.0v6.0.1+92 more2015-02-16
CVE-2014-0227 [MEDIUM] CWE-19 CVE-2014-0227: java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.
java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by s
nvd
CVE-2018-1305P3MEDIUMCVSS 6.5≥ 7.0.0, ≤ 7.0.84≥ 8.0.0, ≤ 8.0.49+7 more2018-02-23
CVE-2018-1305 [MEDIUM] CVE-2018-1305: Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to
Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were lo
nvd
CVE-2013-2067P3MEDIUMCVSS 6.8v6.0.21v6.0.24+38 more2013-06-01
CVE-2013-2067 [MEDIUM] CWE-287 CVE-2013-2067: java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in
java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during complet
nvd
CVE-2015-5345P3MEDIUMCVSS 5.3v6.0.0v6.0.1+86 more2016-02-25
CVE-2015-5345 [MEDIUM] CWE-22 CVE-2015-5345: The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9
The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a directory via a URL that lacks a trailing / (slash) character.
nvd
CVE-2026-34500P3MEDIUMCVSS 6.5≥ 9.0.92, < 9.0.117≥ 10.1.22, < 10.1.54+2 more2026-04-09
CVE-2026-34500 [MEDIUM] CWE-287 CVE-2026-34500: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled a
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the i
nvd
CVE-2000-0759P4MEDIUMCVSS 6.4PoCv3.12000-10-20
CVE-2000-0759 [MEDIUM] CVE-2000-0759: Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a
Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.
nvd
CVE-2026-55956P3MEDIUMCVSS 6.5fixed in 9.0.119≥ 10.1.0, < 10.1.56+1 more2026-06-29
CVE-2026-55956 [MEDIUM] CWE-285 CVE-2026-55956: Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for th
Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100
nvd
CVE-2022-45143P3HIGHCVSS 7.5≥ 9.0.40, < 9.0.69v8.5.83+2 more2023-01-03
CVE-2022-45143 [HIGH] CWE-116 CVE-2022-45143: The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not e
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
nvd
CVE-2022-42252P3HIGHCVSS 7.5≥ 8.5.0, < 8.5.83≥ 9.0.0, < 9.0.68+2 more2022-11-01
CVE-2022-42252 [HIGH] CWE-444 CVE-2022-42252: If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 wa
If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was locat
nvd