Apache Tomcat vulnerabilities
272 known vulnerabilities affecting apache/tomcat.
Total CVEs
272
CISA KEV
7
actively exploited
Public exploits
55
Exploited in wild
9
Severity breakdown
CRITICAL25HIGH90MEDIUM141LOW16
Vulnerabilities
Page 7 of 14
CVE-2025-53506P3HIGHCVSS 7.5≥ 9.0.0, ≤ 9.0.106≥ 10.1.0, ≤ 10.1.42+1 more2025-07-10
CVE-2025-53506 [HIGH] CWE-400 CVE-2025-53506: Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowl
Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.
The following versions were EOL at th
nvd
CVE-2001-0590P4MEDIUMCVSS 5.0PoC≤ 3.2.22001-08-02
CVE-2001-0590 [MEDIUM] CVE-2001-0590: Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source
Apache Software Foundation Tomcat Servlet prior to 3.2.2 allows a remote attacker to read the source code to arbitrary 'jsp' files via a malformed URL request which does not end with an HTTP protocol specification (i.e. HTTP/1.0).
nvd
CVE-2021-30640P3MEDIUMCVSS 6.5≥ 7.0.0, < 7.0.109≥ 8.5.0, < 8.5.66+2 more2021-07-12
CVE-2021-30640 [MEDIUM] CWE-116 CVE-2021-30640: A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variatio
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
nvd
CVE-2020-13943P3MEDIUMCVSS 4.3v8.5.0v8.5.1+95 more2020-10-12
CVE-2020-13943 [MEDIUM] CVE-2020-13943: If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0
If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a p
nvd
CVE-2026-68763P3HIGHCVSS 7.5≥ 8.5.59, < 9.0.121≥ 10.1.0, < 10.1.58+1 more2026-08-25
CVE-2026-68763 [HIGH] CWE-400 CVE-2026-68763: Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/
Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120.
The following versions were EOL at the time the CVE was created but are
known to
nvd
CVE-2026-65927P3HIGHCVSS 7.5≥ 8.5.0, < 9.0.121≥ 10.1.0, < 10.1.58+1 more2026-08-25
CVE-2026-65927 [HIGH] CWE-193 CVE-2026-65927: Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes
Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120.
The following versions were EOL at the time
nvd
CVE-2026-24734P3HIGHCVSS 7.5≥ 9.0.83, < 9.0.115≥ 10.1.1, < 10.1.52+47 more2026-02-17
CVE-2026-24734 [HIGH] CWE-20 CVE-2026-24734: Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat.
When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed.
This issue affects Apache Tomcat Native: from 1.3.0
nvd
CVE-2026-29129P3HIGHCVSS 7.5≥ 9.0.114, < 9.0.116≥ 10.1.51, < 10.1.53+1 more2026-04-09
CVE-2026-29129 [HIGH] CWE-327 CVE-2026-29129: Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects
Configured cipher preference order not preserved vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
nvd
CVE-2025-52520P3HIGHCVSS 7.5≥ 9.0.0, < 9.0.107≥ 10.1.0, < 10.1.43+1 more2025-07-10
CVE-2025-52520 [HIGH] CWE-190 CVE-2025-52520: For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache To
For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106.
The following versions were EOL at the time the CVE was created but a
nvd
CVE-2025-52434P3HIGHCVSS 7.5≥ 9.0.0, < 9.0.1072025-07-10
CVE-2025-52434 [HIGH] CWE-362 CVE-2025-52434: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerab
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections.
This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106.
The following versions were EOL at the tim
nvd
CVE-2016-8747P3HIGHCVSS 7.5≥ 8.5.7, < 8.5.10v9.0.02017-03-14
CVE-2016-8747 [HIGH] CWE-200 CVE-2016-8747: An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.
An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request.
nvd
CVE-2018-1304P3MEDIUMCVSS 5.9≥ 7.0.0, ≤ 7.0.84≥ 8.0.0, ≤ 8.0.49+4 more2018-02-28
CVE-2018-1304 [MEDIUM] CVE-2018-1304: The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly ha
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access
nvd
CVE-2021-30639P3HIGHCVSS 7.5v8.5.64v9.0.44+2 more2021-07-12
CVE-2021-30639 [HIGH] CWE-755 CVE-2021-30639: A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An erro
A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the Request object was not reset between requests. This meant that once a non-blocking I/O error occurred, all future requests h
nvd
CVE-2026-34487P3HIGHCVSS 7.5≥ 9.0.13, < 9.0.117≥ 10.1.0, < 10.1.54+1 more2026-04-09
CVE-2026-34487 [HIGH] CWE-532 CVE-2026-34487: Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clusterin
Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.
nvd
CVE-2014-0227P3MEDIUMCVSS 6.4v6.0.0v6.0.1+92 more2015-02-16
CVE-2014-0227 [MEDIUM] CWE-19 CVE-2014-0227: java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.
java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by s
nvd
CVE-2021-42340P3HIGHCVSS 7.5≥ 8.5.60, < 8.5.72≥ 9.0.40, < 9.0.54+3 more2021-10-14
CVE-2021-42340 [HIGH] CWE-772 CVE-2021-42340: The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could le
nvd
CVE-2025-49124P3HIGHCVSS 8.4≥ 9.0.23, < 9.0.106≥ 10.1.0, < 10.1.42+1 more2025-06-16
CVE-2025-49124 [HIGH] CWE-426 CVE-2025-49124: Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the
Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105.
The following versions were EOL at the time the CVE
nvd
CVE-2017-5650P3HIGHCVSS 7.5v8.5.0v8.5.1+12 more2017-04-17
CVE-2017-5650 [HIGH] CWE-404 CVE-2017-5650: In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame f
In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated with that connection that were currently waiting for a WINDOW_UPDATE before allowing the application to write more data. These waiting streams each consumed a thread. A malicious client could therefore cons
nvd
CVE-2024-38286P3HIGHCVSS 7.5≥ 9.0.13, < 9.0.90≥ 10.1.1, < 10.1.25+2 more2024-11-07
CVE-2024-38286 [HIGH] CWE-770 CVE-2024-38286: Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue aff
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7
nvd
CVE-2021-41079P3HIGHCVSS 7.5≥ 8.5.0, < 8.5.64≥ 9.0.0, < 9.0.44+1 more2021-09-16
CVE-2021-41079 [HIGH] CWE-20 CVE-2021-41079: Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.
nvd