Apache Tomcat
Apache Software Foundation- Product type
- Other
- Catalog vulnerabilities
- 121
Severity across 100 analyzed records
en
Severity across 100 analyzed records
Verify to analyze this security profile
As of 09/13/2026, within CyStack's analyzed data, Apache Tomcat has 20 security vulnerabilities published in the last 90 days. Of these, 16 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of Apache Tomcat and determine which vulnerabilities affect that version.
| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-73180Apache Tomcat: Authenticated WebSocket session survives end of HTTP session | Exploitation statusNot known exploited | FixYes | Published08/25/2026 | SeverityMedium |
CVE-2026-68763Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset | Exploitation statusNot known exploited | FixYes | Published08/25/2026 | SeverityHigh |
CVE-2026-68569Apache Tomcat: Principal lookup can fail open in some cases | Exploitation statusNot known exploited | FixYes | Published08/25/2026 | SeverityHigh |
CVE-2026-68525Apache Tomcat: Redirect after FORM auth may bypass method specific constraints | Exploitation statusNot known exploited | FixYes | Published08/25/2026 | SeverityCritical |
CVE-2026-66422Apache Tomcat: Servlet role references can bypass declarative role constraints | Exploitation statusNot known exploited | FixYes | Published08/25/2026 | SeverityHigh |
CVE-2026-65927Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control | Exploitation statusNot known exploited | FixYes | Published08/25/2026 | SeverityHigh |
CVE-2026-65905Apache Tomcat: Limited replay attack possible with DIGEST authentication | Exploitation statusNot known exploited | FixYes | Published08/25/2026 | SeverityCritical |
CVE-2026-65637Apache Tomcat: HTTP/2 no-authority bypass of strict SNI validation - CVE-2026-32990 fix incomplete | Exploitation statusNot known exploited | FixYes | Published08/25/2026 | SeverityCritical |
CVE-2026-65183Apache Tomcat: TOCTOU when setting specific permissions for Unix Domain Sockets | Exploitation statusNot known exploited | FixYes | Published08/25/2026 | SeverityHigh |
CVE-2026-65182Apache Tomcat: Bypass longest prefix security constraint | Exploitation statusNot known exploited | FixYes | Published08/25/2026 | SeverityCritical |
CVE-2026-66299Apache Tomcat: DoS via WebSocket chat example | Exploitation statusNot known exploited | FixYes | Published07/28/2026 | SeverityHigh |
CVE-2026-59084Apache Tomcat: EncryptInterceptor requirements not clearly documented | Exploitation statusNot known exploited | FixYes | Published07/14/2026 | SeverityCritical |
CVE-2026-59083Apache Tomcat: Incorrect URL decoding in RewriteValve may allow security control bypass | Exploitation statusNot known exploited | FixYes | Published07/14/2026 | SeverityCritical |
CVE-2026-55957Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind | Exploitation statusNot known exploited | FixYes | Published06/29/2026 | SeverityHigh |
CVE-2026-55956Apache Tomcat: Security constraints for default servlet ignored method | Exploitation statusNot known exploited | FixYes | Published06/29/2026 | SeverityMedium |
CVE-2026-55955Apache Tomcat: EncryptInterceptor not protected against replay attacks | Exploitation statusNot known exploited | FixYes | Published06/29/2026 | SeverityMedium |
CVE-2026-55276Apache Tomcat: Logged effective web.xml is incomplete | Exploitation statusNot known exploited | FixYes | Published06/29/2026 | SeverityCritical |
CVE-2026-53434Apache Tomcat: Invalid CRL configuration doesn't trigger failure for FFM Connector | Exploitation statusNot known exploited | FixYes | Published06/29/2026 | SeverityCritical |
CVE-2026-53404Apache Tomcat: Bad ornext processing in RewriteValve | Exploitation statusNot known exploited | FixYes | Published06/29/2026 | SeverityHigh |
CVE-2026-50229Apache Tomcat: XSS in number guess example | Exploitation statusNot known exploited | FixYes | Published06/29/2026 | SeverityMedium |
CVE-2026-43515Apache Tomcat: Security constraints not correctly applied | Exploitation statusNot known exploited | FixYes | Published05/12/2026 | SeverityCritical |
CVE-2026-43514Apache Tomcat: AJP secret compared in non-constant time | Exploitation statusNot known exploited | FixYes | Published05/12/2026 | SeverityLow |
CVE-2026-43513Apache Tomcat: LockOutRealm treats user names as case-sensitive | Exploitation statusNot known exploited | FixYes | Published05/12/2026 | SeverityHigh |
CVE-2026-43512Apache Tomcat: Digest authenticator will authenticate any unknown user | Exploitation statusNot known exploited | FixYes | Published05/12/2026 | SeverityCritical |
CVE-2026-41293Apache Tomcat: HTTP/2 request headers not validated | Exploitation statusNot known exploited | FixYes | Published05/12/2026 | SeverityCritical |
CVE-2026-42498Apache Tomcat: WebSocket authentication header exposure | Exploitation statusNot known exploited | FixYes | Published05/12/2026 | SeverityHigh |
CVE-2026-41284Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling | Exploitation statusNot known exploited | FixYes | Published05/12/2026 | SeverityHigh |
CVE-2026-34500Apache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled | Exploitation statusNot known exploited | FixYes | Published04/09/2026 | SeverityMedium |
CVE-2026-34487Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token | Exploitation statusNot known exploited | FixYes | Published04/09/2026 | SeverityHigh |
CVE-2026-34486Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor | Exploitation statusKEV | FixNot confirmed | Published04/09/2026 | SeverityHigh |
CVE-2026-34483Apache Tomcat: Incomplete escaping of JSON access logs | Exploitation statusNot known exploited | FixYes | Published04/09/2026 | SeverityHigh |
CVE-2026-32990Apache Tomcat: Fix for CVE-2025-66614 is incomplete | Exploitation statusNot known exploited | FixYes | Published04/09/2026 | SeverityMedium |
CVE-2026-29146Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default | Exploitation statusNot known exploited | FixYes | Published04/09/2026 | SeverityHigh |
CVE-2026-29145Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled | Exploitation statusNot known exploited | FixYes | Published04/09/2026 | SeverityCritical |
CVE-2026-29129Apache Tomcat: TLS cipher order is not preserved | Exploitation statusNot known exploited | FixYes | Published04/09/2026 | SeverityHigh |
CVE-2026-25854Apache Tomcat: Occasionally open redirect | Exploitation statusNot known exploited | FixYes | Published04/09/2026 | SeverityMedium |
CVE-2026-24880Apache Tomcat: Request smuggling via invalid chunk extension | Exploitation statusNot known exploited | FixYes | Published04/09/2026 | SeverityHigh |
CVE-2026-24734Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass | Exploitation statusNot known exploited | FixYes | Published02/17/2026 | SeverityHigh |
CVE-2026-24733Apache Tomcat: Security constraint bypass with HTTP/0.9 | Exploitation statusNot known exploited | FixYes | Published02/17/2026 | SeverityMedium |
CVE-2025-66614Apache Tomcat: Client certificate verification bypass due to virtual host mapping | Exploitation statusNot known exploited | FixYes | Published02/17/2026 | SeverityHigh |
CVE-2025-61795Apache Tomcat: Delayed cleaning of multi-part upload temporary files may lead to DoS | Exploitation statusNot known exploited | FixYes | Published10/27/2025 | SeverityMedium |
CVE-2025-55752Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled | Exploitation statusNot known exploited | FixYes | Published10/27/2025 | SeverityHigh |
CVE-2025-55754Apache Tomcat: console manipulation via escape sequences in log messages | Exploitation statusNot known exploited | FixYes | Published10/27/2025 | SeverityCritical |
CVE-2025-55668Apache Tomcat: session fixation via rewrite valve | Exploitation statusNot known exploited | FixYes | Published08/13/2025 | SeverityMedium |
CVE-2025-48989Apache Tomcat: h2 DoS - Made You Reset | Exploitation statusNot known exploited | FixYes | Published08/13/2025 | SeverityHigh |
CVE-2025-53506Apache Tomcat: DoS via excessive h2 streams at connection start | Exploitation statusNot known exploited | FixYes | Published07/10/2025 | SeverityHigh |
CVE-2025-52520Apache Tomcat: DoS via integer overflow in multipart file upload | Exploitation statusNot known exploited | FixYes | Published07/10/2025 | SeverityHigh |
CVE-2025-52434Apache Tomcat: APR/Native Connector crash leading to DoS | Exploitation statusNot known exploited | FixYes | Published07/10/2025 | SeverityHigh |
CVE-2025-49124Apache Tomcat: exe side-loading via icalcs.exe in Tomcat installer for Windows | Exploitation statusNot known exploited | FixYes | Published06/16/2025 | SeverityHigh |
CVE-2025-49125Apache Tomcat: Security constraint bypass for pre/post-resources | Exploitation statusNot known exploited | FixYes | Published06/16/2025 | SeverityHigh |
CVE-2025-48988Apache Tomcat: FileUpload large number of parts with headers DoS | Exploitation statusNot known exploited | FixYes | Published06/16/2025 | SeverityHigh |
CVE-2025-46701Apache Tomcat: Security constraint bypass for CGI scripts | Exploitation statusNot known exploited | FixYes | Published05/29/2025 | SeverityHigh |
CVE-2025-31651Apache Tomcat: Bypass of rules in Rewrite Valve | Exploitation statusNot known exploited | FixYes | Published04/28/2025 | SeverityCritical |
CVE-2025-31650Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame | Exploitation statusNot known exploited | FixYes | Published04/28/2025 | SeverityHigh |
CVE-2025-24813Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT | Exploitation statusKEV | FixYes | Published03/10/2025 | SeverityCritical |
CVE-2024-56337Apache Tomcat: RCE due to TOCTOU issue in JSP compilation - CVE-2024-50379 mitigation was incomplete | Exploitation statusNot known exploited | FixYes | Published12/20/2024 | SeverityCritical |
CVE-2024-54677Apache Tomcat: DoS in examples web application | Exploitation statusNot known exploited | FixYes | Published12/17/2024 | SeverityMedium |
CVE-2024-50379Apache Tomcat: RCE due to TOCTOU issue in JSP compilation | Exploitation statusPublic exploit | FixYes | Published12/17/2024 | SeverityCritical |
CVE-2024-52318Apache Tomcat: Incorrect JSP tag recycling leads to XSS | Exploitation statusNot known exploited | FixNot confirmed | Published11/18/2024 | SeverityMedium |
CVE-2024-52317Apache Tomcat: Request/response mix-up with HTTP/2 | Exploitation statusNot known exploited | FixYes | Published11/18/2024 | SeverityMedium |
CVE-2024-52316Apache Tomcat: Authentication bypass when using Jakarta Authentication API | Exploitation statusNot known exploited | FixYes | Published11/18/2024 | SeverityCritical |
CVE-2024-38286Apache Tomcat: Denial of Service | Exploitation statusNot known exploited | FixYes | Published11/07/2024 | SeverityHigh |
CVE-2024-34750Apache Tomcat: HTTP/2 excess header handling DoS | Exploitation statusNot known exploited | FixYes | Published07/03/2024 | SeverityHigh |
CVE-2024-23672Apache Tomcat: WebSocket DoS with incomplete closing handshake | Exploitation statusNot known exploited | FixYes | Published03/13/2024 | SeverityMedium |
CVE-2024-24549Apache Tomcat: HTTP/2 header handling DoS | Exploitation statusNot known exploited | FixYes | Published03/13/2024 | SeverityHigh |
CVE-2024-21733Apache Tomcat: Leaking of unrelated request bodies in default error page | Exploitation statusNot known exploited | FixYes | Published01/19/2024 | SeverityMedium |
CVE-2023-46589Apache Tomcat: HTTP request smuggling via malformed trailer headers | Exploitation statusNot known exploited | FixYes | Published11/28/2023 | SeverityHigh |
CVE-2023-45648Apache Tomcat: Trailer header parsing too lenient | Exploitation statusNot known exploited | FixYes | Published10/10/2023 | SeverityMedium |
CVE-2023-42795Apache Tomcat: Failure during request clean-up leads to sensitive data leaking to subsequent requests | Exploitation statusNot known exploited | FixYes | Published10/10/2023 | SeverityMedium |
CVE-2023-42794Apache Tomcat: FileUpload: DoS due to accumulation of temporary files on Windows | Exploitation statusNot confirmed | FixYes | Published10/10/2023 | SeverityUnknown |
CVE-2023-41080Apache Tomcat: Open redirect with FORM authentication | Exploitation statusNot known exploited | FixYes | Published08/25/2023 | SeverityUnknown |
CVE-2023-34981Apache Tomcat: AJP response header mix-up | Exploitation statusNot known exploited | FixNot confirmed | Published06/21/2023 | SeverityHigh |
CVE-2023-28709Apache Tomcat: Fix for CVE-2023-24998 is incomplete | Exploitation statusNot known exploited | FixYes | Published05/22/2023 | SeverityUnknown |
CVE-2023-28708Apache Tomcat: JSESSIONID Cookie missing secure attribute in some configurations | Exploitation statusNot known exploited | FixYes | Published03/22/2023 | SeverityMedium |
CVE-2023-24998Apache Commons FileUpload, Apache Tomcat: FileUpload DoS with excessive parts | Exploitation statusNot confirmed | FixYes | Published02/20/2023 | SeverityUnknown |
CVE-2022-45143Apache Tomcat: JsonErrorReportValve escaping | Exploitation statusNot known exploited | FixNot confirmed | Published01/03/2023 | SeverityUnknown |
CVE-2022-42252Apache Tomcat request smuggling via malformed content-length | Exploitation statusNot known exploited | FixYes | Published11/01/2022 | SeverityHigh |
CVE-2021-43980Apache Tomcat: Information disclosure | Exploitation statusNot known exploited | FixNot confirmed | Published09/28/2022 | SeverityLow |
CVE-2022-34305XSS in examples web application | Exploitation statusNot confirmed | FixNot confirmed | Published06/23/2022 | SeverityUnknown |
CVE-2022-25762Response mix-up with WebSocket concurrent send and close | Exploitation statusNot confirmed | FixNot confirmed | Published05/13/2022 | SeverityUnknown |
CVE-2022-29885EncryptInterceptor does not provide complete protection on insecure networks | Exploitation statusNot confirmed | FixNot confirmed | Published05/12/2022 | SeverityUnknown |
CVE-2022-23181Local privilege escalation with FileStore | Exploitation statusNot confirmed | FixNot confirmed | Published01/27/2022 | SeverityUnknown |
CVE-2021-42340DoS via memory leak with WebSocket connections | Exploitation statusNot confirmed | FixNot confirmed | Published10/14/2021 | SeverityUnknown |
CVE-2021-41079Apache Tomcat DoS with unexpected TLS packet | Exploitation statusNot confirmed | FixNot confirmed | Published09/16/2021 | SeverityUnknown |
CVE-2021-33037Incorrect Transfer-Encoding handling with HTTP/1.0 | Exploitation statusNot confirmed | FixNot confirmed | Published07/12/2021 | SeverityUnknown |
CVE-2021-30640Auth weakness in JNDIRealm | Exploitation statusNot confirmed | FixNot confirmed | Published07/12/2021 | SeverityUnknown |
CVE-2021-30639DoS after non-blocking IO error | Exploitation statusNot confirmed | FixNot confirmed | Published07/12/2021 | SeverityUnknown |
CVE-2021-25329Incomplete fix for CVE-2020-9484 | Exploitation statusNot confirmed | FixYes | Published03/01/2021 | SeverityUnknown |
CVE-2021-25122Apache Tomcat h2c request mix-up | Exploitation statusNot confirmed | FixYes | Published03/01/2021 | SeverityUnknown |
CVE-2021-24122Apache Tomcat information disclosure | Exploitation statusNot confirmed | FixYes | Published01/14/2021 | SeverityUnknown |
CVE-2020-17527Apache Tomcat: Request header mix-up between HTTP/2 streams | Exploitation statusNot confirmed | FixNot confirmed | Published12/03/2020 | SeverityUnknown |
CVE-2019-12418 | Exploitation statusNot confirmed | FixNot confirmed | Published12/23/2019 | SeverityUnknown |
CVE-2019-17563 | Exploitation statusNot confirmed | FixNot confirmed | Published12/23/2019 | SeverityUnknown |
CVE-2018-11784 | Exploitation statusNot confirmed | FixNot confirmed | Published10/04/2018 | SeverityUnknown |
CVE-2018-8037 | Exploitation statusNot confirmed | FixNot confirmed | Published08/02/2018 | SeverityUnknown |
CVE-2018-1336 | Exploitation statusNot known exploited | FixNot confirmed | Published08/02/2018 | SeverityUnknown |
CVE-2018-8034 | Exploitation statusNot known exploited | FixNot confirmed | Published08/01/2018 | SeverityHigh |
CVE-2018-8014 | Exploitation statusNot confirmed | FixNot confirmed | Published05/16/2018 | SeverityUnknown |
CVE-2018-1304 | Exploitation statusNot confirmed | FixNot confirmed | Published02/28/2018 | SeverityUnknown |
CVE-2018-1305 | Exploitation statusNot confirmed | FixNot confirmed | Published02/23/2018 | SeverityUnknown |
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan