Apache Software Foundation Apache Tomcat vulnerabilities
114 known vulnerabilities affecting apache_software_foundation/apache_tomcat.
Total CVEs
114
CISA KEV
4
actively exploited
Public exploits
13
Exploited in wild
5
Severity breakdown
CRITICAL22HIGH58MEDIUM31LOW3
Vulnerabilities
Page 6 of 6
CVE-2017-15706P4MEDIUMCVSS 5.3v9.0.0.M22 to 9.0.1v8.5.16 to 8.5.23+2 more2018-01-31
CVE-2017-15706 [MEDIUM] CWE-358 CVE-2017-15706: As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to
As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify which script to execute. The update was not correct. As a result, some scripts may have failed to execute as expec
nvd
CVE-2024-52318P4MEDIUMCVSS 6.1v11.0.0v10.1.31+1 more2024-11-18
CVE-2024-52318 [MEDIUM] CWE-326 CVE-2024-52318: Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomc
Incorrect object recycling and reuse vulnerability in Apache Tomcat.
This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96.
Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue.
nvd
CVE-2026-25854P4MEDIUMCVSS 6.1≥ 11.0.0-M1, ≤ 11.0.18≥ 10.1.0-M1, ≤ 10.1.52+2 more2026-04-09
CVE-2026-25854 [MEDIUM] CWE-601 CVE-2026-25854: Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via th
Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.M23 through 9.0.115, from 8.5.30 through 8.5.100.
Other, unsupported versions may also be affected
Users are re
nvd
CVE-2026-66299P4MEDIUMCVSS 5.3≥ 11.0.0-M20, ≤ 11.0.24≥ 10.1.24, ≤ 10.1.57+1 more2026-07-28
CVE-2026-66299 [MEDIUM] CWE-400 CVE-2026-66299: Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example. This iss
Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket chat example.
This issue affects Apache Tomcat: from 11.0.0-M20 through 11.0.24, from 10.1.24 through 10.1.57, from 9.0.89 through 9.0.120. Users who have followed the security guidance to remove the examples web application are not affected by this issue.
Users are recomm
nvd
CVE-2023-42795P4MEDIUMCVSS 5.3≥ 11.0.0-M1, ≤ 11.0.0-M11≥ 10.1.0-M1, ≤ 10.1.13+2 more2023-10-10
CVE-2023-42795 [MEDIUM] CWE-459 CVE-2023-42795: Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache
Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could
cause Tomcat to skip some parts of the recycling process leading to
information leaking from the curren
nvd
CVE-2024-54677P4MEDIUMCVSS 5.3≥ 11.0.0-M1, ≤ 11.0.1≥ 10.1.0-M1, ≤ 10.1.33+2 more2024-12-17
CVE-2024-54677 [MEDIUM] CWE-400 CVE-2024-54677: Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97.
The following versions were EOL at the time the CVE was created but are
known to be aff
nvd
CVE-2025-61795P4MEDIUMCVSS 5.3≥ 11.0.0-M1, ≤ 11.0.11≥ 10.1.0-M1, ≤ 10.1.46+2 more2025-10-27
CVE-2025-61795 [MEDIUM] CWE-404 CVE-2025-61795: Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (includi
Improper Resource Shutdown or Release vulnerability in Apache Tomcat.
If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memor
nvd
CVE-2026-32990P4MEDIUMCVSS 5.3≥ 11.0.20, ≤ 11.0.24≥ 10.1.53, ≤ 10.1.57+1 more2026-04-09
CVE-2026-32990 [MEDIUM] CWE-20 CVE-2026-32990: Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614.
Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614.
This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115.
Users are recommended to upgrade to version 11.0.20, 10.1.53 or 9.0.116, which fix the issue.
nvd
CVE-2023-42794P4MEDIUMCVSS 5.9≥ 9.0.70, ≤ 9.0.80≥ 8.5.85, ≤ 8.5.932023-10-10
CVE-2023-42794 [MEDIUM] CWE-459 CVE-2023-42794: Incomplete Cleanup vulnerability in Apache Tomcat. The internal fork of Commons FileUpload packaged
Incomplete Cleanup vulnerability in Apache Tomcat.
The internal fork of Commons FileUpload packaged with Apache Tomcat 9.0.70 through 9.0.80 and 8.5.85 through 8.5.93 included an unreleased,
in progress refactoring that exposed a potential denial of service on
Windows if a web application opened a stream for an uploaded file but
failed to close the
nvd
CVE-2017-7674P4MEDIUMCVSS 4.3v9.0.0.M1 to 9.0.0.M21v8.5.0 to 8.5.15+2 more2017-08-11
CVE-2017-7674 [MEDIUM] CWE-345 CVE-2017-7674: The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0
The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server side cache poisoning in some circumstances.
nvd
CVE-2023-28708P4MEDIUMCVSS 4.3≥ 11.0.0-M1, ≤ 11.0.0-M2≥ 10.1.0-M1, ≤ 10.1.5+2 more2023-03-22
CVE-2023-28708 [MEDIUM] CWE-523 CVE-2023-28708: When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include t
When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting th
nvd
CVE-2026-24733P4LOWCVSS 3.7≥ 11.0.0-M1, ≤ 11.0.14≥ 10.1.0-M1, ≤ 10.1.49+2 more2026-02-17
CVE-2026-24733 [LOW] CWE-20 CVE-2026-24733: Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests t
Improper Input Validation vulnerability in Apache Tomcat.
Tomcat did not limit HTTP/0.9 requests to the GET method. If a security
constraint was configured to allow HEAD requests to a URI but deny GET
requests, the user could bypass that constraint on GET requests by
sending a (specification invalid) HEAD request using HTTP/0.9.
This issue affects Apa
nvd
CVE-2026-43514P4LOWCVSS 3.7≥ 11.0.0-M1, ≤ 11.0.21≥ 10.1.0-M1, ≤ 10.1.54+3 more2026-05-12
CVE-2026-43514 [LOW] CWE-208 CVE-2026-43514: Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue
Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109.
Older unsupported versions may also be affected.
Users are recommended to upgrade
nvd
CVE-2021-43980P4LOWCVSS 3.7v10.1.0-M1 to 10.1.0-M12v10.0.0-M1 to 10.0.18+2 more2022-09-28
CVE-2021-43980 [LOW] CWE-362 CVE-2021-43980: The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported t
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Proc
nvd
← Previous6 / 6