Skip to main content

Vendor/product archive

apache / tomcat CVEs

Beta · best-effort

264 CVEs tagged to apache / tomcat21 Critical, 86 High, 141 Medium, 16 Low, 0 Unrated.

CVE-2026-24880

Published Apr 9, 2026

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: fro…

CVSS 7.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-24734

Published Feb 17, 2026

Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did…

CVSS 7.5 · High
evidence mentions
11
Buzz score
37.9
Vendor/product tagsBeta · best-effort

CVE-2026-24733

Published Feb 17, 2026

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD reques…

CVSS 3.7 · Low
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-66614

Published Feb 17, 2026

Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The fol…

CVSS 9.1 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-61795

Published Oct 27, 2025

Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary cop…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-55754

Published Oct 27, 2025

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running i…

CVSS 9.6 · Critical
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-55752

Published Oct 27, 2025

Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This int…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-55668

Published Aug 13, 2025

Session Fixation vulnerability in Apache Tomcat via rewrite valve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.41, from 9.0.0.M1…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-48989

Published Aug 13, 2025

Improper Resource Shutdown or Release vulnerability in Apache Tomcat made Tomcat vulnerable to the made you reset attack. This issue affects Apache Tomcat: from 11.0.0-M1 through…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-53506

Published Jul 10, 2025

Uncontrolled Resource Consumption vulnerability in Apache Tomcat if an HTTP/2 client did not acknowledge the initial settings frame that reduces the maximum permitted concurrent s…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-52520

Published Jul 10, 2025

For some unlikely configurations of multipart upload, an Integer Overflow vulnerability in Apache Tomcat could lead to a DoS via bypassing of size limits. This issue affects Apac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-52434

Published Jul 10, 2025

Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in Apache Tomcat when using the APR/Native connector. This was particular…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49125

Published Jun 16, 2025

Authentication Bypass Using an Alternate Path or Channel vulnerability in Apache Tomcat.  When using PreResources or PostResources mounted other than at the root of the web applic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-49124

Published Jun 16, 2025

Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path.…

CVSS 8.4 · High
Vendor/product tagsBeta · best-effort

CVE-2025-48988

Published Jun 16, 2025

Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.7, from 10.1.0-M1 through 10.1.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-46701

Published May 29, 2025

Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component o…

CVSS 7.3 · High
Vendor/product tagsBeta · best-effort

CVE-2025-31651

Published Apr 28, 2025

Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. For a subset of unlikely rewrite rule configurations, it was possible for a speciall…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-31650

Published Apr 28, 2025

Improper Input Validation vulnerability in Apache Tomcat. Incorrect error handling for some invalid HTTP priority headers resulted in incomplete clean-up of the failed request whi…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-52318

Published Nov 18, 2024

Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52317

Published Nov 18, 2024

Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or respon…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-52316

Published Nov 18, 2024

Unchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may th…

CVSS 9.8 · Critical
evidence mentions
4
Buzz score
24.1
Vendor/product tagsBeta · best-effort
Showing 26-50 of 264 CVEsPage 2 of 11