Debian Tomcat9 vulnerabilities
67 known vulnerabilities affecting debian/tomcat9.
Total CVEs
67
CISA KEV
3
actively exploited
Public exploits
10
Exploited in wild
4
Severity breakdown
CRITICAL8HIGH37MEDIUM15LOW7
Vulnerabilities
Page 3 of 4
CVE-2021-30640P3MEDIUMCVSS 6.5fixed in tomcat9 9.0.43-2 (bookworm)2021
CVE-2021-30640 [MEDIUM] CVE-2021-30640: tomcat9 - A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authent...
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 to 10.0.5; 9.0.0.M1 to 9.0.45; 8.5.0 to 8.5.65.
Scope: local
bookworm: resolved (fixed in 9.0.43-2)
bullseye: resolved (fixed in
debian
CVE-2020-13943P3MEDIUMCVSS 4.3fixed in tomcat9 9.0.38-1 (bookworm)2020
CVE-2020-13943 [MEDIUM] CVE-2020-13943: tomcat9 - If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1...
If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation of the HTTP/2 protocol), it was possible that a subsequent request made on that connection could contain HTTP headers - including HTTP/2 pseudo headers - from a previou
debian
CVE-2026-24734P3HIGHCVSS 7.5fixed in tomcat10 10.1.52-1~deb12u1 (bookworm)2026
CVE-2026-24734 [HIGH] CVE-2026-24734: tomcat10 - Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. ...
Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verification or freshness checks on the OCSP response which could allow certificate revocation to be bypassed. This issue affects Apache Tomcat Native: from 1.3.0 through 1.3.4
debian
CVE-2025-52434P3HIGHCVSS 7.5fixed in tomcat9 9.0.70-2 (bookworm)2025
CVE-2025-52434 [HIGH] CVE-2025-52434: tomcat9 - Concurrent Execution using Shared Resource with Improper Synchronization ('Race ...
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particularly noticeable with client initiated closes of HTTP/2 connections. This issue affects Apache Tomcat: from 9.0.0.M1 through 9.0.106. The following versions were EOL at the time the CVE was cr
debian
CVE-2021-42340P3HIGHCVSS 7.5fixed in tomcat9 9.0.54-1 (bookworm)2021
CVE-2021-42340 [HIGH] CVE-2021-42340: tomcat9 - The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1...
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not released for WebSocket connections once the connection was closed. This created a memory leak that, over time, could lead to a denial
debian
CVE-2024-38286P3HIGHCVSS 8.6fixed in tomcat10 10.1.34-0+deb12u1 (bookworm)2024
CVE-2024-38286 [HIGH] CVE-2024-38286: tomcat10 - Allocation of Resources Without Limits or Throttling vulnerability in Apache Tom...
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Other EO
debian
CVE-2021-41079P3HIGHCVSS 7.5fixed in tomcat9 9.0.53-1 (bookworm)2021
CVE-2021-41079 [HIGH] CVE-2021-41079: tomcat9 - Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did no...
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to trigger an infinite loop resulting in a denial of service.
Scope: local
bookworm: resolved (fixed in 9.0.53-1)
bullseye: resolved (
debian
CVE-2022-45143P3HIGHCVSS 7.5fixed in tomcat9 9.0.70-1 (bookworm)2022
CVE-2022-45143 [HIGH] CVE-2022-45143: tomcat9 - The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1...
The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from user provided data and it was therefore possible for users to supply values that invalidated or manipulated the JSON output.
Scope: local
bookworm: resolved (fixed in 9.0.7
debian
CVE-2022-42252P3HIGHCVSS 7.5fixed in tomcat9 9.0.68-1 (bookworm)2022
CVE-2022-42252 [HIGH] CVE-2022-42252: tomcat9 - If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10...
If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default for 8.5.x only), Tomcat did not reject a request containing an invalid Content-Length header making a request smuggling attack possible if Tomcat was located behind a rev
debian
CVE-2021-25329P3HIGHCVSS 7.0fixed in tomcat9 9.0.43-1 (bookworm)2021
CVE-2021-25329 [HIGH] CVE-2021-25329: tomcat9 - The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to ...
The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously publi
debian
CVE-2024-52317P3LOWCVSS 6.5fixed in tomcat10 10.1.31-1 (forky)2024
CVE-2024-52317 [MEDIUM] CVE-2024-52317: tomcat10 - Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect...
Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95. Users are recommended to upgrade t
debian
CVE-2024-23672P3MEDIUMCVSS 6.3fixed in tomcat10 10.1.6-1+deb12u2 (bookworm)2024
CVE-2024-23672 [MEDIUM] CVE-2024-23672: tomcat10 - Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was ...
Denial of Service via incomplete cleanup vulnerability in Apache Tomcat. It was possible for WebSocket clients to keep WebSocket connections open leading to increased resource consumption.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M16, from 10.1.0-M1 through 10.1.18, from 9.0.0-M1 through 9.0.85, from 8.5.0 through 8.5.98. Older, EOL versions
debian
CVE-2023-34981P3LOWCVSS 7.5fixed in tomcat10 10.1.10-1 (forky)2023
CVE-2023-34981 [HIGH] CVE-2023-34981: tomcat10 - A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74...
A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an information leak.
Scop
debian
CVE-2025-55668P3MEDIUMCVSS 6.5fixed in tomcat10 10.1.52-1~deb12u1 (bookworm)2025
CVE-2025-55668 [MEDIUM] CVE-2025-55668: tomcat10 - Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue a...
Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1 through 9.0.105. Older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.8, 10.1.42 or 9.0.106, which fix the issue.
Scope: local
bookworm: resolved (fi
debian
CVE-2023-41080P3MEDIUMCVSS 6.1fixed in tomcat10 10.1.6-1+deb12u1 (bookworm)2023
CVE-2023-41080 [MEDIUM] CVE-2023-41080: tomcat10 - URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authen...
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.79 and from 8.5.0 through 8.5.92. Older, EOL versions may also be affected. The vulnerability is limited to the ROOT (default)
debian
CVE-2024-21733P3MEDIUMCVSS 5.3fixed in tomcat9 9.0.53-1 (bookworm)2024
CVE-2024-21733 [MEDIUM] CVE-2024-21733: tomcat9 - Generation of Error Message Containing Sensitive Information vulnerability in Ap...
Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL versions may also be affected. Users are recommended to upgrade to version 8.5.64 onwards or 9.0.44 onwards, which contain a fix for the issue.
Scope: local
bookworm: reso
debian
CVE-2019-12418P3HIGHCVSS 7.0fixed in tomcat9 9.0.31-1 (bookworm)2019
CVE-2019-12418 [HIGH] CVE-2019-12418: tomcat9 - When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is conf...
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can
debian
CVE-2022-23181P4HIGHCVSS 7.0fixed in tomcat9 9.0.58-1 (bookworm)2022
CVE-2022-23181 [HIGH] CVE-2022-23181: tomcat9 - The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerabil...
The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions with the privileges of the user that the Tomcat process is using. This issue is only exploitable when Tomcat is configured to persis
debian
CVE-2024-52318P4LOWCVSS 6.1fixed in tomcat10 10.1.33-1 (forky)2024
CVE-2024-52318 [MEDIUM] CVE-2024-52318: tomcat10 - Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue...
Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue.
Scope: local
bookworm: resolved
forky: resolved (fixed in 10.1.33-1)
sid: resolved (fixed in 10.1.33-1)
trixie: resolved (fixed in 10.1.33-1)
debian
CVE-2020-1935P4MEDIUMCVSS 4.8fixed in tomcat9 9.0.31-1 (bookworm)2020
CVE-2020-1935 [MEDIUM] CVE-2020-1935: tomcat9 - In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTT...
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a
debian