cbcvebase.

Apache Software Foundation Apache Tomcat vulnerabilities

103 known vulnerabilities affecting apache_software_foundation/apache_tomcat.

Total CVEs
103
CISA KEV
4
actively exploited
Public exploits
13
Exploited in wild
5
Severity breakdown
CRITICAL19HIGH53MEDIUM28LOW3

Vulnerabilities

Page 4 of 6
CVE-2016-6797P3HIGHCVSS 7.5v9.0.0.M1 to 9.0.0.M9v8.5.0 to 8.5.4+3 more2017-08-10
CVE-2016-6797 [HIGH] CWE-863 CVE-2016-6797: The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0. The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resour
nvd
CVE-2025-52520P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.8≥ 10.1.0-M1, ≤ 10.1.42+2 more2025-07-10
CVE-2025-52520 [HIGH] CWE-190 CVE-2025-52520: For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache To For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but a
nvd
CVE-2021-30640P3MEDIUMCVSS 6.5vApache Tomcat 10 10.0.0-M1 to 10.0.5vApache Tomcat 9 9.0.0.M1 to 9.0.45+2 more2021-07-12
CVE-2021-30640 [MEDIUM] CWE-116 CVE-2021-30640: A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variatio A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
nvd
CVE-2026-24734P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.17≥ 10.1.0-M7, ≤ 10.1.51+1 more2026-02-17
CVE-2026-24734 [HIGH] CWE-20 CVE-2026-24734: Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native: from 1.3.0
nvd
CVE-2026-29129P3HIGHCVSS 7.5≥ 11.0.16, ≤ 11.0.18≥ 10.1.51, ≤ 10.1.52+1 more2026-04-09
CVE-2026-29129 [HIGH] CWE-327 CVE-2026-29129: Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
nvd
CVE-2025-52434P3HIGHCVSS 7.5≥ 9.0.0.M1, ≤ 9.0.106≥ 8.5.0, ≤ 8.5.1002025-07-10
CVE-2025-52434 [HIGH] CWE-362 CVE-2025-52434: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerab Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106. The following versions were EOL at the tim
nvd
CVE-2016-8747P3HIGHCVSS 7.5v8.5.7 to 8.5.9v9.0.0.M11 to 9.0.0.M152017-03-14
CVE-2016-8747 [HIGH] CWE-200 CVE-2016-8747: An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0. An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request.
nvd
CVE-2021-30639P3HIGHCVSS 7.5vApache Tomcat 10 10.0.3 to 10.0.4vApache Tomcat 9 9.0.44+1 more2021-07-12
CVE-2021-30639 [HIGH] CWE-755 CVE-2021-30639: A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An erro A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the Request object was not reset between requests. This meant that once a non-blocking I/O error occurred, all future requests h
nvd
CVE-2026-34487P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.20≥ 10.1.0-M1, ≤ 10.1.53+1 more2026-04-09
CVE-2026-34487 [HIGH] CWE-532 CVE-2026-34487: Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clusterin Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.
nvd
CVE-2021-42340P3HIGHCVSS 7.5vApache Tomcat 10 10.0.0-M10 to 10.0.11vApache Tomcat 10 10.1.0-M1 to 10.1.0-M5+2 more2021-10-14
CVE-2021-42340 [HIGH] CWE-772 CVE-2021-42340: The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could le
nvd
CVE-2025-49124P3HIGHCVSS 8.4≥ 11.0.0-M1, ≤ 11.0.7≥ 10.1.0, ≤ 10.1.41+3 more2025-06-16
CVE-2025-49124 [HIGH] CWE-426 CVE-2025-49124: Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. The following versions were EOL at the time the CVE
nvd
CVE-2017-5650P3HIGHCVSS 7.5v9.0.0.M1 to 9.0.0.M18v8.5.0 to 8.5.122017-04-17
CVE-2017-5650 [HIGH] CWE-404 CVE-2017-5650: In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame f In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated with that connection that were currently waiting for a WINDOW_UPDATE before allowing the application to write more data. These waiting streams each consumed a thread. A malicious client could therefore cons
nvd
CVE-2024-38286P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.0-M20≥ 10.1.0-M1, ≤ 10.1.24+3 more2024-11-07
CVE-2024-38286 [HIGH] CWE-770 CVE-2024-38286: Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue aff Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7
nvd
CVE-2018-1304P3MEDIUMCVSS 5.9vApache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49, 7.0.0 to 7.0.842018-02-28
CVE-2018-1304 [MEDIUM] CVE-2018-1304: The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly ha The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access
nvd
CVE-2021-41079P3HIGHCVSS 7.5vApache Tomcat 8.5 8.5.0 to 8.5.63vApache Tomcat 9 9.0.0-M1 to 9.0.43+1 more2021-09-16
CVE-2021-41079 [HIGH] CWE-20 CVE-2021-41079: Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.
nvd
CVE-2018-1305P3MEDIUMCVSS 6.5vApache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49, 7.0.0 to 7.0.842018-02-23
CVE-2018-1305 [MEDIUM] CVE-2018-1305: Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were lo
nvd
CVE-2026-34500P3MEDIUMCVSS 6.5≥ 11.0.0-M14, ≤ 11.0.20≥ 10.1.22, ≤ 10.1.53+1 more2026-04-09
CVE-2026-34500 [MEDIUM] CWE-287 CVE-2026-34500: CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled a CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20, from 10.1.22 through 10.1.53, from 9.0.92 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fixes the i
nvd
CVE-2026-55956P3MEDIUMCVSS 6.5≥ 11.0.0-M1, ≤ 11.0.22≥ 10.1.0-M1, ≤ 10.1.55+3 more2026-06-29
CVE-2026-55956 [MEDIUM] CWE-285 CVE-2026-55956: Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for th Improper Authorization vulnerability in Apache Tomcat leads to security constraints specified for the default servlet ignoring any method or method omission configured as part of the constraint. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.22, from 10.1.0-M1 through 10.1.55, from 9.0.0.M1 through 9.0.118, from 8.5.0 through 8.5.100
nvd
CVE-2022-45143P3HIGHCVSS 7.5≥ 10.1.0-M1, ≤ 10.1.1≥ 9.0.40, ≤ 9.0.68+1 more2023-01-03
CVE-2022-45143 [HIGH] CWE-116 CVE-2022-45143: The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not e The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
nvd
CVE-2022-42252P3HIGHCVSS 7.5≥ 10.1.0-M1, ≤ 10.1.0≥ 10.0.0-M1, ≤ 10.0.26+2 more2022-11-01
CVE-2022-42252 [HIGH] CWE-444 CVE-2022-42252: If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 wa If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was locat
nvd
Apache Software Foundation Apache Tomcat vulnerabilities | cvebase