cbcvebase.

Apache Software Foundation Apache Tomcat vulnerabilities

114 known vulnerabilities affecting apache_software_foundation/apache_tomcat.

Total CVEs
114
CISA KEV
4
actively exploited
Public exploits
13
Exploited in wild
5
Severity breakdown
CRITICAL22HIGH58MEDIUM31LOW3

Vulnerabilities

Page 1 of 6
CVE-2016-3427P1CRITICALCVSS 9.8KEVPoCvbefore 6.0.48v7.x before 7.0.73+3 more2016-04-21
CVE-2016-3427 [CRITICAL] CWE-284 CVE-2016-3427: Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRocki Unspecified vulnerability in Oracle Java SE 6u113, 7u99, and 8u77; Java SE Embedded 8u77; and JRockit R28.3.9 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to JMX.
nvd
CVE-2025-24813P1CRITICALCVSS 9.8KEVPoC≥ 11.0.0-M1, ≤ 11.0.2≥ 10.1.0-M1, ≤ 10.1.34+2 more2025-03-10
CVE-2025-24813 [CRITICAL] CWE-44 CVE-2025-24813: Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information dis Path Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following
nvd
CVE-2017-12615P1HIGHCVSS 8.1KEVPoCRansomwarev7.0.0 to 7.0.792017-09-19
CVE-2017-12615 [HIGH] CWE-434 CVE-2017-12615: When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the r When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server.
nvd
CVE-2017-12617P1HIGHCVSS 8.1KEVPoCv9.0.0.M1 to 9.0.0v8.5.0 to 8.5.22+2 more2017-10-04
CVE-2017-12617 [HIGH] CWE-434 CVE-2017-12617: When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0. When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code
nvd
CVE-2022-34305P1MEDIUMCVSS 6.1ExploitedPoCvApache Tomcat 8.5 8.5.50 to 8.5.81vApache Tomcat 9 9.0.30 to 9.0.64+2 more2022-06-23
CVE-2022-34305 [MEDIUM] CWE-79 CVE-2022-34305: In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.8 In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability.
nvd
CVE-2022-29885P2HIGHCVSS 7.5PoCvApache Tomcat 10.1 10.1.0-M1 to 10.1.0-M14vApache Tomcat 10 10.0.0-M1 to 10.0.20+2 more2022-05-12
CVE-2022-29885 [HIGH] CWE-400 CVE-2022-29885: The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 a The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was not correct. While the EncryptInterceptor does provide confidentiality and integrity protection, it does not protec
nvd
CVE-2025-31650P2HIGHCVSS 7.5PoC≥ 9.0.76, ≤ 9.0.102≥ 10.1.10, ≤ 10.1.39+2 more2025-04-28
CVE-2025-31650 [HIGH] CWE-459 CVE-2025-31650: Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request which created a memory leak. A large number of such requests could trigger an OutOfMemoryException resulting in a denial of service. This issue affects Apache Tomcat: from 9.0.7
nvd
CVE-2020-9484P2HIGHCVSS 7.0PoCvApache Tomcat 10.1 10.1.0-M1 to 10.1.0-M8vApache Tomcat 10.0 10.0.0-M5 to 10.0.14+2 more2020-05-20
CVE-2020-9484 [HIGH] CWE-502 CVE-2020-9484: When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7. When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassN
nvd
CVE-2026-29146P2HIGHCVSS 7.5PoCv11.0.20v10.1.53+1 more2026-04-09
CVE-2026-29146 [HIGH] CWE-209 CVE-2026-29146: Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.109. Users are recommended to upgrade to version 11.0.19, 10.1.53 and 9.0.116
nvd
CVE-2016-5018P2CRITICALCVSS 9.1PoCv9.0.0.M1 to 9.0.0.M9v8.5.0 to 8.5.4+3 more2017-08-10
CVE-2016-5018 [CRITICAL] CVE-2016-5018: In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 a malicious web application was able to bypass a configured SecurityManager via a Tomcat utility method that was accessible to web applications.
nvd
CVE-2024-50379P2CRITICALCVSS 9.8≥ 11.0.0-M1, ≤ 11.0.1≥ 10.1.0-M1, ≤ 10.1.33+2 more2024-12-17
CVE-2024-50379 [CRITICAL] CWE-367 CVE-2024-50379: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tom Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability during JSP compilation in Apache Tomcat permits an RCE on case insensitive file systems when the default servlet is enabled for write (non-default configuration). This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.
nvd
CVE-2018-11784P3MEDIUMCVSS 4.3PoCv9.0.0.M1 to 9.0.11v8.5.0 to 8.5.33+1 more2018-10-04
CVE-2018-11784 [MEDIUM] CWE-601 CVE-2018-11784: When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to When the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a directory (e.g. redirecting to '/foo/' when the user requested '/foo') a specially crafted URL could be used to cause the redirect to be generated to any URI of the attackers choice.
nvd
CVE-2025-55752P2HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.10≥ 10.1.0-M1, ≤ 10.1.44+2 more2025-10-27
CVE-2025-55752 [HIGH] CWE-23 CVE-2025-55752: Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regressi Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that rewrite query parameters to the URL, an attacker could manipulate the request URI to bypass security constraints including the pr
nvd
CVE-2017-12616P2HIGHCVSS 7.5v7.0.0 to 7.0.802017-09-19
CVE-2017-12616 [HIGH] CWE-200 CVE-2017-12616: When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security When using a VirtualDirContext with Apache Tomcat 7.0.0 to 7.0.80 it was possible to bypass security constraints and/or view the source code of JSPs for resources served by the VirtualDirContext using a specially crafted request.
nvd
CVE-2025-48988P2HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.7≥ 10.1.0-M1, ≤ 10.1.41+2 more2025-06-16
CVE-2025-48988 [HIGH] CWE-770 CVE-2025-48988: Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue aff Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versio
nvd
CVE-2024-52316P2CRITICALCVSS 9.8≥ 11.0.0-M1, ≤ 11.0.0-M26≥ 10.1.0-M1, ≤ 10.1.30+2 more2024-11-18
CVE-2024-52316 [CRITICAL] CWE-391 CVE-2024-52316: Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Ja Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to by
nvd
CVE-2026-41293P2CRITICALCVSS 9.8≥ 11.0.0-M1, ≤ 11.0.21≥ 10.1.0-M1, ≤ 10.1.54+3 more2026-05-12
CVE-2026-41293 [CRITICAL] CWE-20 CVE-2026-41293: Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11 Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of support versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the
nvd
CVE-2023-24998P2HIGHCVSS 7.5≥ 11.0.0-M2, ≤ 11.0.0-M4≥ 10.1.5, ≤ 10.1.7+2 more2023-02-20
CVE-2023-24998 [HIGH] CWE-770 CVE-2023-24998: Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resu Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads. Note that, like all of the file upload limits, the new configuration option (FileUploadBase#setFileCountMax) is not enabled by default and must be e
nvd
CVE-2026-65905P2CRITICALCVSS 9.8≥ 11.0.0-M1, ≤ 11.0.24≥ 10.1.0-M1, ≤ 10.1.57+3 more2026-08-25
CVE-2026-65905 [CRITICAL] CWE-294 CVE-2026-65905: Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, b Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the replay window then that request is replayable once only while the associated nonceCount remains within the replay
nvd
CVE-2026-50229P3MEDIUMCVSS 6.1PoC≥ 11.0.0-M1, ≤ 11.0.22≥ 10.1.0-M1, ≤ 10.1.55+3 more2026-06-29
CVE-2026-50229 [MEDIUM] CWE-80 CVE-2026-50229: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the n Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in the number guess example for Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Other versions that have re
nvd
Apache Software Foundation Apache Tomcat vulnerabilities | cvebase