Apache Software Foundation Apache Tomcat vulnerabilities
114 known vulnerabilities affecting apache_software_foundation/apache_tomcat.
Total CVEs
114
CISA KEV
4
actively exploited
Public exploits
13
Exploited in wild
5
Severity breakdown
CRITICAL22HIGH58MEDIUM31LOW3
Vulnerabilities
Page 3 of 6
CVE-2026-55957P3HIGHCVSS 7.3≥ 11.0.0-M1, ≤ 11.0.4≥ 10.1.0-M1, ≤ 10.1.36+3 more2026-06-29
CVE-2026-55957 [HIGH] CWE-304 CVE-2026-55957: Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was config
Missing Critical Step in Authentication vulnerability in Apache Tomcat when the JNDIRealm was configured to authenticate binds using GSSAPI allowed attackers to authenticate without provided the correct password.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.4, from 10.1.0-M1 through 10.1.36, from 9.0.0.M1 through 9.0.100, from 8.5.0
nvd
CVE-2017-5647P3HIGHCVSS 7.5v9.0.0.M1 to 9.0.0.M18v8.5.0 to 8.5.12+3 more2017-04-17
CVE-2017-5647 [HIGH] CWE-200 CVE-2017-5647: A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5
A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined request being lost when send file processing of the previous request completed. This could result in responses appearing to be sent for the w
nvd
CVE-2025-49125P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.7≥ 10.1.0-M1, ≤ 10.1.41+2 more2025-06-16
CVE-2025-49125 [HIGH] CWE-288 CVE-2025-49125: Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using
Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat. When using PreResources or PostResources mounted other than at the root of the web application, it was possible to access those resources via an unexpected path. That path was likely not to be protected by the same security constraints as the expected path, allowin
nvd
CVE-2022-25762P3HIGHCVSS 8.6vApache Tomcat 9 9.0.0.M1 to 9.0.20vApache Tomcat 8.5 8.5.0 to 8.5.752022-05-13
CVE-2022-25762 [HIGH] CWE-404 CVE-2022-25762: If a web application sends a WebSocket message concurrently with the WebSocket connection closing wh
If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use the socket after it has been closed. The error handling triggered in this case could cause the a pooled object to b
nvd
CVE-2019-17563P3HIGHCVSS 7.5v9.0.0.M1 to 9.0.29v8.5.0 to 8.5.49+1 more2019-12-23
CVE-2019-17563 [HIGH] CWE-384 CVE-2019-17563: When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.
nvd
CVE-2016-8745P3HIGHCVSS 7.5v9.0.0.M1 to 9.0.0.M13v8.5.0 to 8.5.8+3 more2017-08-10
CVE-2016-8745 [HIGH] CWE-388 CVE-2016-8745: A bug in the error handling of the send file code for the NIO HTTP connector in Apache Tomcat 9.0.0.
A bug in the error handling of the send file code for the NIO HTTP connector in Apache Tomcat 9.0.0.M1 to 9.0.0.M13, 8.5.0 to 8.5.8, 8.0.0.RC1 to 8.0.39, 7.0.0 to 7.0.73 and 6.0.16 to 6.0.48 resulted in the current Processor object being added to the Processor cache multiple times. This in turn meant that the same Processor could be used for concurrent
nvd
CVE-2017-5648P3CRITICALCVSS 9.1v9.0.0.M1 to 9.0.0.M17v8.5.0 to 8.5.11+2 more2017-04-17
CVE-2017-5648 [CRITICAL] CWE-668 CVE-2017-5648: While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tom
While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use the appropriate facade object. When running an untrusted application under a SecurityManager, it was therefore possible for that untrusted application to
nvd
CVE-2018-1336P3HIGHCVSS 7.5v9.0.0.M9 to 9.0.7v8.5.0 to 8.5.30+2 more2018-08-02
CVE-2018-1336 [HIGH] CWE-835 CVE-2018-1336: An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an in
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
nvd
CVE-2026-66422P3HIGHCVSS 8.1≥ 11.0.0-M1, ≤ 11.0.24≥ 10.1.0-M1, ≤ 10.1.57+3 more2026-08-25
CVE-2026-66422 [HIGH] CWE-285 CVE-2026-66422: Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being i
Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref definitions being incorrectly used as role aliases within the Realm in additional to the correct usage with Request.isUserInRole().
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.25 through 9.0.120.
The follo
nvd
CVE-2017-5651P3CRITICALCVSS 9.8v9.0.0.M1 to 9.0.0.M18v8.5.0 to 8.5.122017-04-17
CVE-2017-5651 [CRITICAL] CVE-2017-5651: In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors i
In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processing. If the send file processing completed quickly, it was possible for the Processor to be added to the processor cache twice. This could result in the same Processor being used for multiple requests which in tu
nvd
CVE-2026-24880P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.18≥ 10.1.0-M1, ≤ 10.1.52+3 more2026-04-09
CVE-2026-24880 [HIGH] CWE-444 CVE-2026-24880: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Ap
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M1 through 9.0.115, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Other, unsupported version
nvd
CVE-2017-5664P3HIGHCVSS 7.5v9.0.0.M1 to 9.0.0.M20v8.5.0 to 8.5.14+2 more2017-06-06
CVE-2017-5664 [HIGH] CWE-755 CVE-2017-5664: The error page mechanism of the Java Servlet Specification requires that, when an error occurs and a
The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is configured for the error that occurred, the original request and response are forwarded to the error page. This means that the request is presented to the error page with the original HTTP method. If the error page is a static file, expect
nvd
CVE-2017-7675P3HIGHCVSS 7.5v9.0.0.M1 to 9.0.0.M21v8.5.0 to 8.5.152017-08-11
CVE-2017-7675 [HIGH] CWE-22 CVE-2017-7675: The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a numb
The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. It was therefore possible to bypass security constraints using a specially crafted URL.
nvd
CVE-2026-65183P3HIGHCVSS 8.1≥ 11.0.0-M1, ≤ 11.0.24≥ 10.1.0-M1, ≤ 10.1.57+1 more2026-08-25
CVE-2026-65183 [HIGH] CWE-367 CVE-2026-65183: Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix
Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat when creating unix domain sockets allows an unauthorised local user to access the unix domain socket.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.42 through 9.0.120.
Users are recommended to upgrade to vers
nvd
CVE-2026-42498P3HIGHCVSS 7.3≥ 11.0.0-M1, ≤ 11.0.21≥ 10.1.0-M1, ≤ 10.1.54+3 more2026-05-12
CVE-2026-42498 [HIGH] CWE-200 CVE-2026-42498: Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerabi
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 through 9.0.117, from 8.5.24 through 8.5.100, from 7.0.83 through 7.0.109.
Users are recommended to upgrade to version
nvd
CVE-2025-48989P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.9≥ 10.1.0-M1, ≤ 10.1.43+1 more2025-08-13
CVE-2025-48989 [HIGH] CWE-404 CVE-2025-48989: Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the m
Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.9, from 10.1.0-M1 through 10.1.43 and from 9.0.0.M1 through 9.0.107. Older, EOL versions may also be affected.
Users are recommended to upgrade to one of versions 11.0
nvd
CVE-2025-46701P3HIGHCVSS 7.3≥ 11.0.0-M1, ≤ 11.0.6≥ 10.1.0-M1, ≤ 10.1.40+2 more2025-05-29
CVE-2025-46701 [HIGH] CWE-178 CVE-2025-46701: Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security c
Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to the CGI servlet.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.6, from 10.1.0-M1 through 10.1.40, from 9.0.0.M1 through 9.0.104.
The follow
nvd
CVE-2026-43513P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.21≥ 10.1.0-M1, ≤ 10.1.54+3 more2026-05-12
CVE-2026-43513 [HIGH] CWE-178 CVE-2026-43513: Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue af
Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Older unsupported versions may also be affected.
Users are recommended to upgrade
nvd
CVE-2026-53404P3HIGHCVSS 7.3≥ 11.0.0-M1, ≤ 11.0.22≥ 10.1.0-M1, ≤ 10.1.55+2 more2026-06-29
CVE-2026-53404 [HIGH] CWE-670 CVE-2026-53404: Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant th
Always-Incorrect Control Flow Implementation vulnerability in Apache Tomcat's rewrite valve meant that if the first condition in an OR chain matched, subsequent non-OR conditions were skipped.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100. Ot
nvd
CVE-2021-24122P3MEDIUMCVSS 5.9≥ Apache Tomcat 10, < 10.0.0-M10≥ Apache Tomcat 9, < 9.0.40+2 more2021-01-14
CVE-2021-24122 [MEDIUM] CWE-200 CVE-2021-24122: When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10
When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to JSP source code disclosure in some configurations. The root cause was the unexpected behaviour of the JRE API File.getCanonicalPath() which in turn was
nvd