cbcvebase.

Apache Software Foundation Apache Tomcat vulnerabilities

114 known vulnerabilities affecting apache_software_foundation/apache_tomcat.

Total CVEs
114
CISA KEV
4
actively exploited
Public exploits
13
Exploited in wild
5
Severity breakdown
CRITICAL22HIGH58MEDIUM31LOW3

Vulnerabilities

Page 2 of 6
CVE-2025-55754P2CRITICALCVSS 9.6≥ 11.0.0-M1, ≤ 11.0.10≥ 10.1.0-M1, ≤ 10.1.44+2 more2025-10-27
CVE-2025-55754 [CRITICAL] CWE-150 CVE-2025-55754: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomca Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console supported ANSI escape sequences, it was possible for an attacker to use a specially crafted URL to inject ANSI e
nvd
CVE-2026-43512P2CRITICALCVSS 9.8≥ 11.0.0-M1, ≤ 11.0.21≥ 10.1.0-M1, ≤ 10.1.54+3 more2026-05-12
CVE-2026-43512 [CRITICAL] CWE-592 CVE-2026-43512: DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. T DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0. Older unsupported versions any also be affect Users are recommended to upg
nvd
CVE-2025-31651P2CRITICALCVSS 9.8≥ 11.0.0-M1, ≤ 11.0.5≥ 10.1.0-M1, ≤ 10.1.39+2 more2025-04-28
CVE-2025-31651 [CRITICAL] CWE-116 CVE-2025-31651: Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a specially crafted request to bypass some rewrite rules. If those rewrite rules effectively enforced security constraints, those constraints could be bypassed. This issue affects A
nvd
CVE-2026-68525P2CRITICALCVSS 9.1≥ 11.0.0-M1, ≤ 11.0.24≥ 10.1.0-M1, ≤ 10.1.57+3 more2026-08-25
CVE-2026-68525 [CRITICAL] CWE-863 CVE-2026-68525: Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypa Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions we
nvd
CVE-2025-66614P2CRITICALCVSS 9.1≥ 11.0.15, ≤ 11.0.19≥ 10.1.50, ≤ 10.1.52+1 more2026-02-17
CVE-2025-66614 [CRITICAL] CWE-20 CVE-2025-66614: Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 1 Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate t
nvd
CVE-2023-45648P3MEDIUMCVSS 5.3PoC≥ 11.0.0-M1, ≤ 11.0.0-M11≥ 10.1.0-M1, ≤ 10.1.13+2 more2023-10-10
CVE-2023-45648 [MEDIUM] CWE-20 CVE-2023-45648: Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, f Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leadin
nvd
CVE-2026-55276P2CRITICALCVSS 9.1≥ 11.0.0-M1, ≤ 11.0.22≥ 10.1.0-M1, ≤ 10.1.55+2 more2026-06-29
CVE-2026-55276 [CRITICAL] CWE-670 CVE-2026-55276: Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat meant that special roles and empty authorisation constraints were not included when the effective web.xml was logged. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.10
nvd
CVE-2026-43515P2CRITICALCVSS 9.1≥ 11.0.0-M1, ≤ 11.0.21≥ 10.1.0-M1, ≤ 10.1.54+3 more2026-05-12
CVE-2026-43515 [CRITICAL] CWE-285 CVE-2026-43515: Improper Authorization vulnerability when multiple method constraints define an HTTP method for the Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgra
nvd
CVE-2026-29145P2CRITICALCVSS 9.1≥ 11.0.0-M1, ≤ 11.0.18≥ 10.1.0-M7, ≤ 10.1.52+1 more2026-04-09
CVE-2026-29145 [CRITICAL] CWE-287 CVE-2026-29145: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled v CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 through 10.1.52, from 9.0.83 through 9.0.115; Apache Tomcat Native: from 1.1.23 through 1.1.34, from 1.2.0 through
nvd
CVE-2026-59084P2CRITICALCVSS 9.1≥ 11.0.0-M1, ≤ 11.0.23≥ 10.1.0-M1, ≤ 10.1.56+3 more2026-07-14
CVE-2026-59084 [CRITICAL] CWE-1059 CVE-2026-59084: Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to secure Insufficient Technical Documentation vulnerability in Apache Tomcat since the requirements to securely configure the EncryptInterceptor were not clearly documented. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.13 through 9.0.119, from 8.5.38 through 8.5.100, from 7.0.100 through 7.0.1
nvd
CVE-2018-8014P2CRITICALCVSS 9.8v9.0.0.M1 to 9.0.8v8.5.0 to 8.5.31+2 more2018-05-16
CVE-2018-8014 [CRITICAL] CWE-1188 CVE-2018-8014: The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5. The defaults settings for the CORS filter provided in Apache Tomcat 9.0.0.M1 to 9.0.8, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, 7.0.41 to 7.0.88 are insecure and enable 'supportsCredentials' for all origins. It is expected that users of the CORS filter will have configured it appropriately for their environment rather than using it in the default conf
nvd
CVE-2021-33037P3MEDIUMCVSS 5.3vApache Tomcat 10 10.0.0-M1 to 10.0.6vApache Tomcat 9 9.0.0.M1 to 9.0.46+1 more2021-07-12
CVE-2021-33037 [MEDIUM] CWE-444 CVE-2021-33037: Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse th Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse proxy. Specifically: - Tomcat incorrectly ignored the transfer encoding header if the client declared it would only
nvd
CVE-2026-53434P2CRITICALCVSS 9.1≥ 11.0.0-M1, ≤ 11.0.22≥ 10.1.0-M7, ≤ 10.1.55+1 more2026-06-29
CVE-2026-53434 [CRITICAL] CWE-390 CVE-2026-53434: Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for Detection of Error Condition Without Action vulnerability in Apache Tomcat when configuring CRLs for a FFM based connector. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M7 through 10.1.55, from 9.0.83 through 9.0.118. Users are recommended to upgrade to version 11.0.23, 10.1.56 or 9.0.119, which fixes the issue.
nvd
CVE-2026-59083P2CRITICALCVSS 9.1≥ 11.0.0-M1, ≤ 11.0.23≥ 10.1.0-M1, ≤ 10.1.56+2 more2026-07-14
CVE-2026-59083 [CRITICAL] CWE-177 CVE-2026-59083: Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allo Improper Handling of URL Encoding (Hex Encoding) vulnerability in Apache Tomcat's rewrite valve allowed security constraint bypass for some configurations. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.23, from 10.1.0-M1 through 10.1.56, from 9.0.0.M1 through 9.0.119, from 8.5.0 through 8.5.100. Other versions that have reached en
nvd
CVE-2024-24549P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.0-M16≥ 10.1.0-M1, ≤ 10.1.18+2 more2024-03-13
CVE-2024-24549 [HIGH] CWE-20 CVE-2024-24549: Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomca Denial of Service due to improper input validation vulnerability for HTTP/2 requests in Apache Tomcat. When processing an HTTP/2 request, if the request exceeded any of the configured limits for headers, the associated HTTP/2 stream was not reset until after all of the headers had been processed.This issue affects Apache Tomcat: from 11.0.0-M1 through
nvd
CVE-2026-65182P2CRITICALCVSS 9.1≥ 11.0.0-M1, ≤ 11.0.24≥ 10.1.0-M1, ≤ 10.1.57+3 more2026-08-25
CVE-2026-65182 [CRITICAL] CWE-284 CVE-2026-65182: Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security co Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0
nvd
CVE-2021-25122P3HIGHCVSS 7.5≥ Apache Tomcat 10, < 10.0.2≥ Apache Tomcat 9, < 9.0.42+1 more2021-03-01
CVE-2021-25122 [HIGH] CWE-200 CVE-2021-25122: When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
nvd
CVE-2018-8034P3HIGHCVSS 7.5v9.0.0.M1 to 9.0.9v8.5.0 to 8.5.31+2 more2018-08-01
CVE-2018-8034 [HIGH] CWE-295 CVE-2018-8034: The host name verification when using TLS with the WebSocket client was missing. It is now enabled b The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.
nvd
CVE-2026-68569P3HIGHCVSS 8.1≥ 11.0.0-M1, ≤ 11.0.24≥ 10.1.0-M1, ≤ 10.1.57+3 more2026-08-25
CVE-2026-68569 [HIGH] CWE-287 CVE-2026-68569: Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT Improper Authentication vulnerability in Apache Tomcat meant that in some circumstances (e.g. CLIENT-CERT, SPNEGO) that a user would be authenticated even if the user did not exist in the DataSourceRealm. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following v
nvd
CVE-2020-17527P3HIGHCVSS 7.5vApache Tomcat 10 10.0.0-M1 to 10.0.0-M9vApache Tomcat 9 9.0.0-M1 to 9.0.39+1 more2020-12-03
CVE-2020-17527 [HIGH] CWE-200 CVE-2020-17527: While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead to an error and the closure of the
nvd
Apache Software Foundation Apache Tomcat vulnerabilities | cvebase