Debian Tomcat9 vulnerabilities
67 known vulnerabilities affecting debian/tomcat9.
Total CVEs
67
CISA KEV
3
actively exploited
Public exploits
10
Exploited in wild
4
Severity breakdown
CRITICAL8HIGH37MEDIUM15LOW7
Vulnerabilities
Page 4 of 4
CVE-2019-17569P4MEDIUMCVSS 4.8fixed in tomcat9 9.0.31-1 (bookworm)2019
CVE-2019-17569 [MEDIUM] CVE-2019-17569: tomcat9 - The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and ...
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Enc
debian
CVE-2025-61795P4MEDIUMCVSS 5.3fixed in tomcat10 10.1.52-1~deb12u1 (bookworm)2025
CVE-2025-61795 [MEDIUM] CVE-2025-61795: tomcat10 - Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an err...
Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memory usage and ap
debian
CVE-2023-42795P4MEDIUMCVSS 5.3fixed in tomcat10 10.1.6-1+deb12u1 (bookworm)2023
CVE-2023-42795 [MEDIUM] CVE-2023-42795: tomcat10 - Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various interna...
Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an error could cause Tomcat to skip some parts of the recycling process leading to information leaking from the current request/res
debian
CVE-2024-54677P4MEDIUMCVSS 5.3fixed in tomcat10 10.1.34-0+deb12u1 (bookworm)2024
CVE-2024-54677 [MEDIUM] CVE-2024-54677: tomcat10 - Uncontrolled Resource Consumption vulnerability in the examples web application ...
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from 9.0.0.M1 through 9.9.97. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 th
debian
CVE-2023-28708P4MEDIUMCVSS 4.3fixed in tomcat10 10.1.6-1 (bookworm)2023
CVE-2023-28708 [MEDIUM] CVE-2023-28708: tomcat10 - When using the RemoteIpFilter with requests received from a reverse proxy via...
When using the RemoteIpFilter with requests received from a reverse proxy via HTTP that include the X-Forwarded-Proto header set to https, session cookies created by Apache Tomcat 11.0.0-M1 to 11.0.0.-M2, 10.1.0-M1 to 10.1.5, 9.0.0-M1 to 9.0.71 and 8.5.0 to 8.5.85 did not include the secure attribute. This could result in the user agent transmitting the session c
debian
CVE-2026-24733P4LOWCVSS 3.7fixed in tomcat10 10.1.52-1~deb12u1 (bookworm)2026
CVE-2026-24733 [LOW] CVE-2026-24733: tomcat10 - Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit...
Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: fro
debian
CVE-2021-43980P4LOWCVSS 3.7fixed in tomcat9 9.0.62-1 (bookworm)2021
CVE-2021-43980 [LOW] CVE-2021-43980: tomcat9 - The simplified implementation of blocking reads and writes introduced in Tomcat ...
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0.0-M1 to 10.0.18, 9.0.0-M1 to 9.0.60 and 8.5.0 to 8.5.77 that could cause client connections to share an Http11Processor instance
debian
← Previous4 / 4