Apache Software Foundation Apache Tomcat vulnerabilities
103 known vulnerabilities affecting apache_software_foundation/apache_tomcat.
Total CVEs
103
CISA KEV
4
actively exploited
Public exploits
13
Exploited in wild
5
Severity breakdown
CRITICAL19HIGH53MEDIUM28LOW3
Vulnerabilities
Page 2 of 6
CVE-2023-24998P3HIGHCVSS 7.5≥ 11.0.0-M2, ≤ 11.0.0-M4≥ 10.1.5, ≤ 10.1.7+2 more2023-02-20
CVE-2023-24998 [HIGH] CWE-770 CVE-2023-24998: Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resu
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.
Note that, like all of the file upload limits, the
new configuration option (FileUploadBase#setFileCountMax) is not
enabled by default and must be e
nvd
CVE-2025-31651P2CRITICALCVSS 9.8≥ 11.0.0-M1, ≤ 11.0.5≥ 10.1.0-M1, ≤ 10.1.39+2 more2025-04-28
CVE-2025-31651 [CRITICAL] CWE-116 CVE-2025-31651: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible
for a specially crafted request to bypass some rewrite rules. If those
rewrite rules effectively enforced security constraints, those
constraints could be bypassed.
This issue affects A
nvd
CVE-2025-66614P2CRITICALCVSS 9.1≥ 11.0.15, ≤ 11.0.19≥ 10.1.50, ≤ 10.1.52+1 more2026-02-17
CVE-2025-66614 [CRITICAL] CWE-20 CVE-2025-66614: Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 1
Improper Input Validation vulnerability.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112.
The following versions were EOL at the time the CVE was created but are
known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected.
Tomcat did not validate t
nvd
CVE-2023-45648P3MEDIUMCVSS 5.3PoC≥ 11.0.0-M1, ≤ 11.0.0-M11≥ 10.1.0-M1, ≤ 10.1.13+2 more2023-10-10
CVE-2023-45648 [MEDIUM] CWE-20 CVE-2023-45648: Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, f
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially
crafted, invalid trailer header could cause Tomcat to treat a single
request as multiple requests leadin
nvd
CVE-2026-55276P2CRITICALCVSS 9.1≥ 11.0.0-M1, ≤ 11.0.22≥ 10.1.0-M1, ≤ 10.1.55+2 more2026-06-29
CVE-2026-55276 [CRITICAL] CWE-670 CVE-2026-55276: Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.10
nvd
CVE-2026-43515P2CRITICALCVSS 9.1≥ 11.0.0-M1, ≤ 11.0.21≥ 10.1.0-M1, ≤ 10.1.54+3 more2026-05-12
CVE-2026-43515 [CRITICAL] CWE-285 CVE-2026-43515: Improper Authorization vulnerability when multiple method constraints define an HTTP method for the
Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Users are recommended to upgra
nvd
CVE-2026-29145P2CRITICALCVSS 9.1≥ 11.0.0-M1, ≤ 11.0.18≥ 10.1.0-M7, ≤ 10.1.52+1 more2026-04-09
CVE-2026-29145 [CRITICAL] CWE-287 CVE-2026-29145: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled v
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through
nvd
CVE-2026-59084P2CRITICALCVSS 9.1≥ 11.0.0-M1, ≤ 11.0.23≥ 10.1.0-M1, ≤ 10.1.56+3 more2026-07-14
CVE-2026-59084 [CRITICAL] CWE-1059 CVE-2026-59084: Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to secure
Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.1
nvd
CVE-2018-8014P2CRITICALCVSS 9.8v9.0.0.M1 to 9.0.8v8.5.0 to 8.5.31+2 more2018-05-16
CVE-2018-8014 [CRITICAL] CWE-1188 CVE-2018-8014: The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.
The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default conf
nvd
CVE-2021-33037P3MEDIUMCVSS 5.3vApache Tomcat 10 10.0.0-M1 to 10.0.6vApache Tomcat 9 9.0.0.M1 to 9.0.46+1 more2021-07-12
CVE-2021-33037 [MEDIUM] CWE-444 CVE-2021-33037: Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse th
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only
nvd
CVE-2026-53434P2CRITICALCVSS 9.1≥ 11.0.0-M1, ≤ 11.0.22≥ 10.1.0-M7, ≤ 10.1.55+1 more2026-06-29
CVE-2026-53434 [CRITICAL] CWE-390 CVE-2026-53434: Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for
Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118.
Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.
nvd
CVE-2026-59083P2CRITICALCVSS 9.1≥ 11.0.0-M1, ≤ 11.0.23≥ 10.1.0-M1, ≤ 10.1.56+2 more2026-07-14
CVE-2026-59083 [CRITICAL] CWE-177 CVE-2026-59083: Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allo
Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached en
nvd
CVE-2024-24549P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.0-M16≥ 10.1.0-M1, ≤ 10.1.18+2 more2024-03-13
CVE-2024-24549 [HIGH] CWE-20 CVE-2024-24549: Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomca
Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through
nvd
CVE-2021-25122P3HIGHCVSS 7.5≥ Apache Tomcat 10, < 10.0.2≥ Apache Tomcat 9, < 9.0.42+1 more2021-03-01
CVE-2021-25122 [HIGH] CWE-200 CVE-2021-25122: When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1
When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
nvd
CVE-2018-8034P3HIGHCVSS 7.5v9.0.0.M1 to 9.0.9v8.5.0 to 8.5.31+2 more2018-08-01
CVE-2018-8034 [HIGH] CWE-295 CVE-2018-8034: The host name verification when using TLS with the WebSocket client was missing. It is now enabled b
The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.
nvd
CVE-2020-17527P3HIGHCVSS 7.5vApache Tomcat 10 10.0.0-M1 to 10.0.0-M9vApache Tomcat 9 9.0.0-M1 to 9.0.39+1 more2020-12-03
CVE-2020-17527 [HIGH] CWE-200 CVE-2020-17527: While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the
nvd
CVE-2026-55957P3HIGHCVSS 7.3≥ 11.0.0-M1, ≤ 11.0.4≥ 10.1.0-M1, ≤ 10.1.36+3 more2026-06-29
CVE-2026-55957 [HIGH] CWE-304 CVE-2026-55957: Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was config
Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0
nvd
CVE-2017-5647P3HIGHCVSS 7.5v9.0.0.M1 to 9.0.0.M18v8.5.0 to 8.5.12+3 more2017-04-17
CVE-2017-5647 [HIGH] CWE-200 CVE-2017-5647: A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5
A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined request being lost when send file processing of the previous request completed. This could result in responses appearing to be sent for the w
nvd
CVE-2025-49125P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.7≥ 10.1.0-M1, ≤ 10.1.41+2 more2025-06-16
CVE-2025-49125 [HIGH] CWE-288 CVE-2025-49125: Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using
Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowin
nvd
CVE-2022-25762P3HIGHCVSS 8.6vApache Tomcat 9 9.0.0.M1 to 9.0.20vApache Tomcat 8.5 8.5.0 to 8.5.752022-05-13
CVE-2022-25762 [HIGH] CWE-404 CVE-2022-25762: If a web application sends a WebSocket message concurrently with the WebSocket connection closing wh
If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to b
nvd