org.apache.tomcat:tomcat
Maven158 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.tomcat:tomcatpage 3 of 4
- CVE-2015-5346HIGHCVSS 8.1EG 8.1✓ Fixed in 7.0.662016-02-25
vulnerable: 7.0.35 ... 7.0.65 (20 versions)
Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote at…
- CVE-2015-5351HIGHCVSS 8.8EG 8.8✓ Fixed in 9.0.0.M22016-02-25
vulnerable: 9.0.0.M1
The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a …
- CVE-2016-0706MEDIUMCVSS 4.3EG 4.3✓ Fixed in 6.0.452016-02-25
Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows…
- CVE-2016-0714HIGHCVSS 8.8EG 8.8✓ Fixed in 6.0.462016-02-25
The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass intended SecurityMana…
- CVE-2016-0762MEDIUMCVSS 5.9EG 5.9✓ Fixed in 6.0.462017-08-10
The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a t…
- CVE-2016-0763MEDIUMCVSS 6.3EG 6.3✓ Fixed in 9.0.0.M32016-02-25
vulnerable: 9.0.0.M1
The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are aut…
- CVE-2016-6794MEDIUMCVSS 5.3EG 5.3✓ Fixed in 9.0.0.M102017-08-10
vulnerable: 9.0.0.M1 ... 9.0.0.M9 (6 versions)
When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to …
- CVE-2016-6796HIGHCVSS 7.5EG 7.5✓ Fixed in 6.0.462017-08-11
A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration param…
- CVE-2016-6797HIGHCVSS 7.5EG 7.5✓ Fixed in 7.0.722017-08-10
vulnerable: 7.0.35 ... 7.0.70 (24 versions)
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explici…
- CVE-2016-6817HIGHCVSS 7.5EG 7.5✓ Fixed in 8.5.82017-08-10
vulnerable: 8.5.0 ... 8.5.6 (6 versions)
The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possible.
- CVE-2016-8747HIGHCVSS 7.5EG 7.5✓ Fixed in 9.0.0.M162017-03-14
vulnerable: 9.0.0.M11, 9.0.0.M13, 9.0.0.M15
An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with …
- CVE-2017-15706MEDIUMCVSS 5.3EG 5.3✓ Fixed in 7.0.842018-01-31
vulnerable: 7.0.79, 7.0.81, 7.0.82
As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify w…
- CVE-2017-5647HIGHCVSS 7.5EG 7.5✓ Fixed in 6.0.532017-04-17
A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined request being lost when s…
- CVE-2017-5650HIGHCVSS 7.5EG 7.5✓ Fixed in 8.5.132017-04-17
vulnerable: 8.5.0 ... 8.5.9 (10 versions)
In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated with that connection that were currently waiting for a WINDOW_UPDATE before allowing the a…
- CVE-2017-5664HIGHCVSS 7.5EG 7.5✓ Fixed in 7.0.782017-06-06
vulnerable: 7.0.35 ... 7.0.77 (29 versions)
The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is configured for the error that occurred, the original request and response are forwarded to the error page. This means that …
- CVE-2017-7674MEDIUMCVSS 4.3EG 4.3✓ Fixed in 7.0.792017-08-11
vulnerable: 7.0.41 ... 7.0.78 (26 versions)
The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server sid…
- CVE-2017-7675HIGHCVSS 7.5EG 7.5✓ Fixed in 8.5.162017-08-11
vulnerable: 8.5.0 ... 8.5.9 (13 versions)
The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. It was therefore possible to bypass security constraints using a speciall…
- CVE-2019-17569MEDIUMCVSS 4.8EG 4.8✓ Fixed in 9.0.312020-02-24
vulnerable: 9.0.29, 9.0.30
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possi…
- CVE-2020-11996HIGHCVSS 7.5EG 7.5✓ Fixed in 8.5.552020-06-26
vulnerable: 8.5.0 ... 8.5.9 (43 versions)
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on con…
- CVE-2020-13934HIGHCVSS 7.5EG 7.5✓ Fixed in 8.5.562020-07-14
vulnerable: 8.5.11 ... 8.5.9 (43 versions)
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryE…
- CVE-2020-13935HIGHCVSS 7.5EG 9.0✓ Fixed in 7.0.1052020-07-14
vulnerable: 7.0.100 ... 7.0.99 (47 versions)
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple reques…
- CVE-2020-1935MEDIUMCVSS 4.8EG 4.8✓ Fixed in 9.0.312020-02-24
vulnerable: 9.0.1 ... 9.0.8 (23 versions)
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP R…
- CVE-2020-8022HIGHCVSS 7.7EG 7.7✓ Fixed in 9.0.352020-06-29
vulnerable: 9.0.1 ... 9.0.8 (26 versions)
A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux E…
- CVE-2021-30639HIGHCVSS 7.5EG 7.5✓ Fixed in 8.5.652021-07-12
vulnerable: 7.0.100 ... 8.5.9 (149 versions)
A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the Request ob…
- CVE-2021-30640MEDIUMCVSS 6.5EG 6.5✓ Fixed in 8.5.652021-07-12
vulnerable: 8.5.0 ... 8.5.9 (52 versions)
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 t…
- CVE-2021-33037MEDIUMCVSS 5.3EG 5.3✓ Fixed in 8.5.682021-07-12
vulnerable: 8.5.0 ... 8.5.9 (54 versions)
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse prox…
- CVE-2021-41079HIGHCVSS 7.5EG 7.5✓ Fixed in 8.5.642021-09-16
vulnerable: 8.5.0 ... 8.5.9 (51 versions)
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to tr…
- CVE-2021-42340HIGHCVSS 7.5EG 7.5✓ Fixed in 8.5.722021-10-14
vulnerable: 8.5.60 ... 8.5.71 (10 versions)
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not rele…
- CVE-2021-43980LOWCVSS 3.7EG 3.7✓ Fixed in 10.1.0-M142022-09-28
vulnerable: 10.1.0-M1 ... 10.1.0-M8 (10 versions)
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0…
- CVE-2022-23181HIGHCVSS 7.0EG 7.0✓ Fixed in 8.5.752022-01-27
vulnerable: 7.0.100 ... 8.5.9 (157 versions)
The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions wit…
- CVE-2022-25762HIGHCVSS 8.6EG 8.6✓ Fixed in 9.0.202022-05-13
vulnerable: 9.0.0.M1 ... 9.0.8 (34 versions)
If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use t…
- CVE-2022-29885HIGHCVSS 7.5EG 7.5✓ Fixed in 8.5.792022-05-12
vulnerable: 8.5.38 ... 8.5.78 (35 versions)
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was n…
- CVE-2022-34305MEDIUMCVSS 6.1EG 6.1✓ Fixed in 8.5.822022-06-23
vulnerable: 8.5.50 ... 8.5.81 (27 versions)
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerabil…
- CVE-2023-41080MEDIUMCVSS 6.1EG 6.1✓ Fixed in 8.5.932023-08-25
vulnerable: 8.5.0 ... 8.5.92 (77 versions)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.7…
- CVE-2023-42795MEDIUMCVSS 5.3EG 5.3✓ Fixed in 8.5.942023-10-10
vulnerable: 8.5.0 ... 8.5.93 (78 versions)
Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an er…
- CVE-2023-45648MEDIUMCVSS 5.3EG 5.3✓ Fixed in 8.5.942023-10-10
vulnerable: 8.5.0 ... 8.5.93 (78 versions)
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A …
- CVE-2024-54677MEDIUMCVSS 5.3EG 5.3✓ Fixed in 9.0.982024-12-17
vulnerable: 9.0.0.M1 ... 9.0.97 (99 versions)
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from …
- CVE-2025-49124HIGHCVSS 8.4EG 8.4✓ Fixed in 11.0.82025-06-16
vulnerable: 11.0.0 ... 11.0.7 (31 versions)
Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.…
- CVE-2025-55752HIGHCVSS 7.5EG 7.52025-10-27
vulnerable: 8.5.100 ... 8.5.99 (80 versions)
Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that r…
- CVE-2025-55754CRITICALCVSS 9.6EG 9.62025-10-27
vulnerable: 8.5.100 ... 8.5.99 (37 versions)
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console s…
- CVE-2025-61795MEDIUMCVSS 5.3EG 5.32025-10-27
vulnerable: 8.5.0 ... 8.5.99 (85 versions)
Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned u…
- CVE-2025-66614CRITICALCVSS 9.1EG 9.1✓ Fixed in 11.0.152026-02-17
vulnerable: 11.0.0 ... 11.0.9 (38 versions)
Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but…
- CVE-2026-24733LOWCVSS 3.7EG 3.7✓ Fixed in 11.0.152026-02-17
vulnerable: 11.0.0 ... 11.0.9 (38 versions)
Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass th…
- CVE-2026-25854MEDIUMCVSS 6.1EG 6.1✓ Fixed in 11.0.202026-04-09
vulnerable: 11.0.0 ... 11.0.9 (40 versions)
Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.…
- CVE-2026-29129HIGHCVSS 7.5EG 7.5✓ Fixed in 11.0.202026-04-09
vulnerable: 11.0.18
Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to upgrade…
- CVE-2026-29145CRITICALCVSS 9.1EG 9.1✓ Fixed in 11.0.202026-04-09
vulnerable: 11.0.0 ... 11.0.9 (40 versions)
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 thro…
- CVE-2026-29146HIGHCVSS 7.5EG 7.52026-04-09
vulnerable: 7.0.100 ... 7.0.109 (8 versions)
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 throu…
- CVE-2026-32990MEDIUMCVSS 5.3EG 5.3✓ Fixed in 11.0.202026-04-09
vulnerable: 11.0.15, 11.0.18
Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are re…
- CVE-2026-34483HIGHCVSS 7.5EG 7.5✓ Fixed in 11.0.212026-04-09
vulnerable: 11.0.0 ... 11.0.9 (41 versions)
Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Us…
- CVE-2026-34486HIGHCVSS 7.5EG 7.5✓ Fixed in 9.0.1172026-04-09
vulnerable: 9.0.116
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to u…
Check whether org.apache.tomcat:tomcat is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.tomcat:tomcat CVEs against the assets you own.
Start Free Scan →