Apache Tomcat vulnerabilities
272 known vulnerabilities affecting apache/tomcat.
Total CVEs
272
CISA KEV
7
actively exploited
Public exploits
55
Exploited in wild
9
Severity breakdown
CRITICAL25HIGH90MEDIUM141LOW16
Vulnerabilities
Page 8 of 14
CVE-2005-4703P4MEDIUMCVSS 5.0PoCv4.0.32005-12-31
CVE-2005-4703 [MEDIUM] CVE-2005-4703: Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive informatio
Apache Tomcat 4.0.3, when running on Windows, allows remote attackers to obtain sensitive information via a request for a file that contains an MS-DOS device name such as lpt9, which leaks the pathname in an error message, as demonstrated by lpt9.xtp using Nikto.
nvd
CVE-2018-1305P3MEDIUMCVSS 6.5≥ 7.0.0, ≤ 7.0.84≥ 8.0.0, ≤ 8.0.49+7 more2018-02-23
CVE-2018-1305 [MEDIUM] CVE-2018-1305: Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to
Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were lo
nvd
CVE-2013-2067P3MEDIUMCVSS 6.8v6.0.21v6.0.24+38 more2013-06-01
CVE-2013-2067 [MEDIUM] CWE-287 CVE-2013-2067: java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in
java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during complet
nvd
CVE-2015-5345P3MEDIUMCVSS 5.3v6.0.0v6.0.1+86 more2016-02-25
CVE-2015-5345 [MEDIUM] CWE-22 CVE-2015-5345: The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9
The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the existence of a directory via a URL that lacks a trailing / (slash) character.
nvd
CVE-2026-34500P3MEDIUMCVSS 6.5≥ 9.0.92, < 9.0.117≥ 10.1.22, < 10.1.54+2 more2026-04-09
CVE-2026-34500 [MEDIUM] CWE-287 CVE-2026-34500: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled a
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116.
Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the i
nvd
CVE-2000-0759P4MEDIUMCVSS 6.4PoCv3.12000-10-20
CVE-2000-0759 [MEDIUM] CVE-2000-0759: Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a
Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.
nvd
CVE-2022-42252P3HIGHCVSS 7.5≥ 8.5.0, < 8.5.83≥ 9.0.0, < 9.0.68+2 more2022-11-01
CVE-2022-42252 [HIGH] CWE-444 CVE-2022-42252: If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 wa
If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was locat
nvd
CVE-2026-55956P3MEDIUMCVSS 6.5fixed in 9.0.119≥ 10.1.0, < 10.1.56+1 more2026-06-29
CVE-2026-55956 [MEDIUM] CWE-285 CVE-2026-55956: Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for th
Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100
nvd
CVE-2026-73180P3MEDIUMCVSS 6.8≥ 7.0.43, ≤ 7.0.109≥ 8.5.0, < 9.0.121+2 more2026-08-25
CVE-2026-73180 [MEDIUM] CWE-613 CVE-2026-73180: Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an a
Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP session was changed after a WebSocket connection had been established under that authenticated HTTP session, the WebSokcet session would not be closed as required by the Jakarta WebSocket specification when the HTTP session ended.
nvd
CVE-2022-45143P3HIGHCVSS 7.5≥ 9.0.40, < 9.0.69v8.5.83+2 more2023-01-03
CVE-2022-45143 [HIGH] CWE-116 CVE-2022-45143: The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not e
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
nvd
CVE-2013-2185P3HIGHCVSS 7.5≤ 7.0.392014-01-19
CVE-2013-2185 [HIGH] CWE-20 CVE-2013-2185: The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat J
The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186. NOTE: this issue is reportedly dispute
nvd
CVE-2016-0763P3MEDIUMCVSS 6.3v7.0.0v7.0.2+63 more2016-02-25
CVE-2016-0763 [MEDIUM] CWE-264 CVE-2016-0763: The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7
The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write
nvd
CVE-2021-25329P3HIGHCVSS 7.0≥ 7.0.0, ≤ 7.0.107≥ 8.5.0, ≤ 8.5.61+39 more2021-03-01
CVE-2021-25329 [HIGH] CVE-2021-25329: The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously
nvd
CVE-2020-8022P3HIGHCVSS 7.8fixed in 8.0.53-29.32.1fixed in 9.0.35-3.39.1+1 more2020-06-29
CVE-2020-8022 [HIGH] CWE-276 CVE-2020-8022: A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage
A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux Enterprise Server 12-SP3-LTSS, SUSE Linux Enterprise Server 12-SP4, SUSE Linux Enterprise Server 12-SP5, SUSE Linux En
nvd
CVE-2008-5515P3MEDIUMCVSS 5.0v4.1.0v4.1.1+78 more2009-06-16
CVE-2008-5515 [MEDIUM] CWE-22 CVE-2008-5515: Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, 6.0.0 through 6.0.18, and possibly earlier versions normalizes the target pathname before filtering the query string when using the RequestDispatcher method, which allows remote attackers to bypass intended access restrictions and conduct directory traversal attacks via .. (dot dot) sequences an
nvd
CVE-2024-52317P3MEDIUMCVSS 6.5≥ 9.0.92, < 9.0.96≥ 10.1.27, < 10.1.31+1 more2024-11-18
CVE-2024-52317 [MEDIUM] CWE-326 CVE-2024-52317: Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the re
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests
could lead to request and/or response mix-up between users.
This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95.
Users are recommen
nvd
CVE-2024-23672P3MEDIUMCVSS 6.3≥ 8.5.0, < 8.5.99≥ 9.0.0, < 9.0.86+2 more2024-03-13
CVE-2024-23672 [MEDIUM] CWE-459 CVE-2024-23672: Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSock
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98.
Olde
nvd
CVE-2026-55955P3MEDIUMCVSS 6.5fixed in 9.0.119≥ 10.1.0, < 10.1.56+1 more2026-06-29
CVE-2026-55955 [MEDIUM] CWE-287 CVE-2026-55955: Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the Encryptio
Improper Authentication vulnerability in Apache Tomcat allowed a replay attack against the EncryptionInterceptor in the cluster component.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.13 through 9.0.18, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109.
Users are recommended to
nvd
CVE-2016-9775P3HIGHCVSS 7.8v6.0v7.0+1 more2017-03-23
CVE-2016-9775 [HIGH] CWE-264 CVE-2016-9775: The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45
The postrm script in the tomcat6 package before 6.0.45+dfsg-1~deb7u3 on Debian wheezy, before 6.0.45+dfsg-1~deb8u1 on Debian jessie, before 6.0.35-1ubuntu3.9 on Ubuntu 12.04 LTS and on Ubuntu 14.04 LTS; the tomcat7 package before 7.0.28-4+deb7u7 on Debian wheezy, before 7.0.56-3+deb8u6 on Debian jessie, before 7.0.52-1ubuntu0.8 on Ubuntu 14.04 LTS, and
nvd
CVE-2016-6817P3HIGHCVSS 7.5v8.5.0v8.5.1+6 more2017-08-10
CVE-2016-6817 [HIGH] CWE-119 CVE-2016-6817: The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infini
The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possible.
nvd