cbcvebase.

Apache Software Foundation Apache Tomcat vulnerabilities

114 known vulnerabilities affecting apache_software_foundation/apache_tomcat.

Total CVEs
114
CISA KEV
4
actively exploited
Public exploits
13
Exploited in wild
5
Severity breakdown
CRITICAL22HIGH58MEDIUM31LOW3

Vulnerabilities

Page 4 of 6
CVE-2026-41284P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.21≥ 10.1.0-M1, ≤ 10.1.54+4 more2026-05-12
CVE-2026-41284 [HIGH] CWE-770 CVE-2026-41284: Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue aff Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117. Older, unsupported versions may also be affected. Users are recommended to upgrade to version [FIXED_VERSION], which fixes the issue.
nvd
CVE-2026-34483P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.20≥ 10.1.0-M1, ≤ 10.1.53+2 more2026-04-09
CVE-2026-34483 [HIGH] CWE-116 CVE-2026-34483: Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117 , which fix the issue.
nvd
CVE-2024-34750P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.0-M20≥ 10.1.0-M1, ≤ 10.1.24+2 more2024-07-03
CVE-2024-34750 [HIGH] CWE-400 CVE-2024-34750: Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apac Improper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections
nvd
CVE-2023-46589P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.0-M10≥ 10.1.0-M1, ≤ 10.1.15+2 more2023-11-28
CVE-2023-46589 [HIGH] CWE-444 CVE-2023-46589: Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, f Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple request
nvd
CVE-2016-6796P3HIGHCVSS 7.5v9.0.0.M1 to 9.0.0.M9v8.5.0 to 8.5.4+3 more2017-08-11
CVE-2016-6796 [HIGH] CVE-2016-6796: A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.
nvd
CVE-2016-6797P3HIGHCVSS 7.5v9.0.0.M1 to 9.0.0.M9v8.5.0 to 8.5.4+3 more2017-08-10
CVE-2016-6797 [HIGH] CWE-863 CVE-2016-6797: The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0. The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resour
nvd
CVE-2025-53506P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.8≥ 10.1.0-M1, ≤ 10.1.42+2 more2025-07-10
CVE-2025-53506 [HIGH] CWE-400 CVE-2025-53506: Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowl Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent streams. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following versions were EOL at th
nvd
CVE-2021-30640P3MEDIUMCVSS 6.5vApache Tomcat 10 10.0.0-M1 to 10.0.5vApache Tomcat 9 9.0.0.M1 to 9.0.45+2 more2021-07-12
CVE-2021-30640 [MEDIUM] CWE-116 CVE-2021-30640: A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variatio A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
nvd
CVE-2026-68763P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.24≥ 10.1.0-M1, ≤ 10.1.57+2 more2026-08-25
CVE-2026-68763 [HIGH] CWE-400 CVE-2026-68763: Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/ Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocation leak in the HTTP/2 backlog tracking when a stream is reset This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.39 through 9.0.120. The following versions were EOL at the time the CVE was created but are known to
nvd
CVE-2026-65927P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.24≥ 10.1.0-M1, ≤ 10.1.57+2 more2026-08-25
CVE-2026-65927 [HIGH] CWE-193 CVE-2026-65927: Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the rewrite valves causes rewrite processing to restart at the second rule rather than the first rule. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.24, from 10.1.0-M1 through 10.1.57, from 9.0.0.M1 through 9.0.120. The following versions were EOL at the time
nvd
CVE-2026-24734P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.17≥ 10.1.0-M7, ≤ 10.1.51+1 more2026-02-17
CVE-2026-24734 [HIGH] CWE-20 CVE-2026-24734: Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native: from 1.3.0
nvd
CVE-2026-29129P3HIGHCVSS 7.5≥ 11.0.16, ≤ 11.0.18≥ 10.1.51, ≤ 10.1.52+1 more2026-04-09
CVE-2026-29129 [HIGH] CWE-327 CVE-2026-29129: Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
nvd
CVE-2025-52520P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.8≥ 10.1.0-M1, ≤ 10.1.42+2 more2025-07-10
CVE-2025-52520 [HIGH] CWE-190 CVE-2025-52520: For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache To For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.8, from 10.1.0-M1 through 10.1.42, from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was created but a
nvd
CVE-2025-52434P3HIGHCVSS 7.5≥ 9.0.0.M1, ≤ 9.0.106≥ 8.5.0, ≤ 8.5.1002025-07-10
CVE-2025-52434 [HIGH] CWE-362 CVE-2025-52434: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerab Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106. The following versions were EOL at the tim
nvd
CVE-2016-8747P3HIGHCVSS 7.5v8.5.7 to 8.5.9v9.0.0.M11 to 9.0.0.M152017-03-14
CVE-2016-8747 [HIGH] CWE-200 CVE-2016-8747: An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0. An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request.
nvd
CVE-2018-1304P3MEDIUMCVSS 5.9vApache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49, 7.0.0 to 7.0.842018-02-28
CVE-2018-1304 [MEDIUM] CVE-2018-1304: The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly ha The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access
nvd
CVE-2021-30639P3HIGHCVSS 7.5vApache Tomcat 10 10.0.3 to 10.0.4vApache Tomcat 9 9.0.44+1 more2021-07-12
CVE-2021-30639 [HIGH] CWE-755 CVE-2021-30639: A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An erro A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the Request object was not reset between requests. This meant that once a non-blocking I/O error occurred, all future requests h
nvd
CVE-2026-34487P3HIGHCVSS 7.5≥ 11.0.0-M1, ≤ 11.0.20≥ 10.1.0-M1, ≤ 10.1.53+1 more2026-04-09
CVE-2026-34487 [HIGH] CWE-532 CVE-2026-34487: Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clusterin Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.13 through 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.
nvd
CVE-2021-42340P3HIGHCVSS 7.5vApache Tomcat 10 10.0.0-M10 to 10.0.11vApache Tomcat 10 10.1.0-M1 to 10.1.0-M5+2 more2021-10-14
CVE-2021-42340 [HIGH] CWE-772 CVE-2021-42340: The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could le
nvd
CVE-2025-49124P3HIGHCVSS 8.4≥ 11.0.0-M1, ≤ 11.0.7≥ 10.1.0, ≤ 10.1.41+3 more2025-06-16
CVE-2025-49124 [HIGH] CWE-426 CVE-2025-49124: Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0 through 10.1.41, from 9.0.23 through 9.0.105. The following versions were EOL at the time the CVE
nvd
Apache Software Foundation Apache Tomcat vulnerabilities | cvebase