org.apache.tomcat:tomcat
Maven164 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.tomcat:tomcatpage 3 of 4
- CVE-2015-5345MEDIUMCVSS 5.3EG 5.3fixed in 9.0.0.M2, 8.0.30, 7.0.68 or 6.0.45, by version range2016-02-25
vulnerable: 7.0.35 ... 7.0.67 (21 versions)
The Mapper component in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.30, and 9.x before 9.0.0.M2 processes redirects before considering security constraints and Filters, which allows remote attackers to determine the …
- CVE-2015-5346HIGHCVSS 8.1EG 8.1fixed in 9.0.0.M2, 8.0.31 or 7.0.66, by version range2016-02-25
vulnerable: 7.0.35 ... 7.0.65 (20 versions)
Session fixation vulnerability in Apache Tomcat 7.x before 7.0.66, 8.x before 8.0.30, and 9.x before 9.0.0.M2, when different session settings are used for deployments of multiple versions of the same web application, might allow remote at…
- CVE-2015-5351HIGHCVSS 8.8EG 8.8fixed in 7.0.68, 8.0.31 or 9.0.0.M2, by version range2016-02-25
vulnerable: 9.0.0.M1
The (1) Manager and (2) Host Manager applications in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 establish sessions and send CSRF tokens for arbitrary new requests, which allows remote attackers to bypass a …
- CVE-2016-0706MEDIUMCVSS 4.3EG 4.3fixed in 9.0.0.M2, 8.0.31 or 6.0.45, by version range2016-02-25
vulnerable: 8.0.1 ... 8.0.9 (21 versions)
Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 does not place org.apache.catalina.manager.StatusManagerServlet on the org/apache/catalina/core/RestrictedServlets.properties list, which allows…
- CVE-2016-0714HIGHCVSS 8.8EG 8.8fixed in 9.0.0.M2, 8.0.32, 7.0.70 or 6.0.46, by version range2016-02-25
vulnerable: 7.0.35 ... 7.0.69 (23 versions)
The session-persistence implementation in Apache Tomcat 6.x before 6.0.45, 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M2 mishandles session attributes, which allows remote authenticated users to bypass intended SecurityMana…
- CVE-2016-0762MEDIUMCVSS 5.9EG 5.9fixed in 9.0.0.M10, 8.5.5, 8.0.37, 7.0.72 or 6.0.46, by version range2017-08-10
vulnerable: 7.0.35 ... 7.0.70 (24 versions)
The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a t…
- CVE-2016-0763MEDIUMCVSS 6.3EG 6.3fixed in 7.0.68, 8.0.32 or 9.0.0.M3, by version range2016-02-25
vulnerable: 9.0.0.M1
The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are aut…
- CVE-2016-6794MEDIUMCVSS 5.3EG 5.3fixed in 6.0.47, 7.0.72, 8.0.37, 8.5.5 or 9.0.0.M10, by version range2017-08-10
vulnerable: 9.0.0.M1 ... 9.0.0.M9 (6 versions)
When a SecurityManager is configured, a web application's ability to read system properties should be controlled by the SecurityManager. In Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70, 6.0.0 to …
- CVE-2016-6796HIGHCVSS 7.5EG 7.5fixed in 9.0.0.M10, 8.5.5, 8.0.37, 7.0.71 or 6.0.46, by version range2017-08-11
vulnerable: 7.0.35 ... 7.0.70 (24 versions)
A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration param…
- CVE-2016-6797HIGHCVSS 7.5EG 7.5fixed in 9.0.0.M10, 8.5.5, 8.0.37 or 7.0.72, by version range2017-08-10
vulnerable: 7.0.35 ... 7.0.70 (24 versions)
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explici…
- CVE-2016-6817HIGHCVSS 7.5EG 7.5fixed in 9.0.0.M12 or 8.5.8, by version range2017-08-10
vulnerable: 8.5.0 ... 8.5.6 (6 versions)
The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possible.
- CVE-2016-8747HIGHCVSS 7.5EG 7.5fixed in 8.5.10 or 9.0.0.M16, by version range2017-03-14
vulnerable: 9.0.0.M11, 9.0.0.M13, 9.0.0.M15
An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with …
- CVE-2017-15706MEDIUMCVSS 5.3EG 5.3fixed in 9.0.2, 8.5.24, 8.0.48 or 7.0.84, by version range2018-01-31
vulnerable: 7.0.79, 7.0.81, 7.0.82
As part of the fix for bug 61201, the documentation for Apache Tomcat 9.0.0.M22 to 9.0.1, 8.5.16 to 8.5.23, 8.0.45 to 8.0.47 and 7.0.79 to 7.0.82 included an updated description of the search algorithm used by the CGI Servlet to identify w…
- CVE-2017-5647HIGHCVSS 7.5EG 7.5fixed in 9.0.0.M19, 8.5.13, 8.0.43, 7.0.77 or 6.0.53, by version range2017-04-17
vulnerable: 7.0.35 ... 7.0.76 (28 versions)
A bug in the handling of the pipelined requests in Apache Tomcat 9.0.0.M1 to 9.0.0.M18, 8.5.0 to 8.5.12, 8.0.0.RC1 to 8.0.42, 7.0.0 to 7.0.76, and 6.0.0 to 6.0.52, when send file was used, results in the pipelined request being lost when s…
- CVE-2017-5650HIGHCVSS 7.5EG 7.5fixed in 9.0.0.M19 or 8.5.13, by version range2017-04-17
vulnerable: 8.5.0 ... 8.5.9 (10 versions)
In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the handling of an HTTP/2 GOAWAY frame for a connection did not close streams associated with that connection that were currently waiting for a WINDOW_UPDATE before allowing the a…
- CVE-2017-5664HIGHCVSS 7.5EG 7.5fixed in 9.0.0.M21, 8.5.15, 8.0.44 or 7.0.78, by version range2017-06-06
vulnerable: 7.0.35 ... 7.0.77 (29 versions)
The error page mechanism of the Java Servlet Specification requires that, when an error occurs and an error page is configured for the error that occurred, the original request and response are forwarded to the error page. This means that …
- CVE-2017-7674MEDIUMCVSS 4.3EG 4.3fixed in 9.0.0.M22, 8.5.16, 8.0.45 or 7.0.79, by version range2017-08-11
vulnerable: 7.0.41 ... 7.0.78 (26 versions)
The CORS Filter in Apache Tomcat 9.0.0.M1 to 9.0.0.M21, 8.5.0 to 8.5.15, 8.0.0.RC1 to 8.0.44 and 7.0.41 to 7.0.78 did not add an HTTP Vary header indicating that the response varies depending on Origin. This permitted client and server sid…
- CVE-2017-7675HIGHCVSS 7.5EG 7.5fixed in 9.0.0.M22 or 8.5.16, by version range2017-08-11
vulnerable: 8.5.0 ... 8.5.9 (13 versions)
The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M21 and 8.5.0 to 8.5.15 bypassed a number of security checks that prevented directory traversal attacks. It was therefore possible to bypass security constraints using a speciall…
- CVE-2019-0221HIGHCVSS 6.1EG 7.6fixed in 9.0.17, 8.5.40 or 7.0.94, by version range2019-05-28
vulnerable: 7.0.35 ... 7.0.93 (41 versions)
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intend…
- CVE-2019-17569MEDIUMCVSS 4.8EG 4.8fixed in 7.0.100, 8.5.51 or 9.0.31, by version range2020-02-24
vulnerable: 9.0.29, 9.0.30
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possi…
- CVE-2020-11996HIGHCVSS 7.5EG 7.5fixed in 10.0.0-M5, 9.0.35 or 8.5.55, by version range2020-06-26
vulnerable: 8.5.0 ... 8.5.9 (43 versions)
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on con…
- CVE-2020-13934HIGHCVSS 7.5EG 8.4fixed in 10.0.0-M6, 9.0.36 or 8.5.56, by version range2020-07-14
vulnerable: 8.5.11 ... 8.5.9 (43 versions)
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryE…
- CVE-2020-13935CRITICALCVSS 7.5EG 9.0fixed in 10.0.0-M7, 9.0.37, 8.5.57 or 7.0.105, by version range2020-07-14
vulnerable: 7.0.100 ... 7.0.99 (47 versions)
The payload length in a WebSocket frame was not correctly validated in Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M1 to 9.0.36, 8.5.0 to 8.5.56 and 7.0.27 to 7.0.104. Invalid payload lengths could trigger an infinite loop. Multiple reques…
- CVE-2020-1935MEDIUMCVSS 4.8EG 4.8fixed in 7.0.100, 8.5.51 or 9.0.31, by version range2020-02-24
vulnerable: 9.0.1 ... 9.0.8 (23 versions)
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP R…
- CVE-2020-8022HIGHCVSS 7.8EG 7.8fixed in 8.0.53 or 9.0.35, by version range2020-06-29
vulnerable: 9.0.1 ... 9.0.8 (26 versions)
A Incorrect Default Permissions vulnerability in the packaging of tomcat on SUSE Enterprise Storage 5, SUSE Linux Enterprise Server 12-SP2-BCL, SUSE Linux Enterprise Server 12-SP2-LTSS, SUSE Linux Enterprise Server 12-SP3-BCL, SUSE Linux E…
- CVE-2021-30639HIGHCVSS 7.5EG 7.5fixed in 10.0.5, 9.0.45 or 8.5.65, by version range2021-07-12
vulnerable: 7.0.100 ... 8.5.9 (149 versions)
A vulnerability in Apache Tomcat allows an attacker to remotely trigger a denial of service. An error introduced as part of a change to improve error handling during non-blocking I/O meant that the error flag associated with the Request ob…
- CVE-2021-30640MEDIUMCVSS 6.5EG 6.5fixed in 10.0.5, 9.0.45 or 8.5.65, by version range2021-07-12
vulnerable: 8.5.0 ... 8.5.9 (52 versions)
A vulnerability in the JNDI Realm of Apache Tomcat allows an attacker to authenticate using variations of a valid user name and/or to bypass some of the protection provided by the LockOut Realm. This issue affects Apache Tomcat 10.0.0-M1 t…
- CVE-2021-33037HIGHCVSS 5.3EG 8.3fixed in 10.0.7, 9.0.48 or 8.5.68, by version range2021-07-12
vulnerable: 8.5.0 ... 8.5.9 (54 versions)
Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did not correctly parse the HTTP transfer-encoding request header in some circumstances leading to the possibility to request smuggling when used with a reverse prox…
- CVE-2021-41079HIGHCVSS 7.5EG 7.5fixed in 10.0.4, 9.0.44 or 8.5.64, by version range2021-09-16
vulnerable: 8.5.0 ... 8.5.9 (51 versions)
Apache Tomcat 8.5.0 to 8.5.63, 9.0.0-M1 to 9.0.43 and 10.0.0-M1 to 10.0.2 did not properly validate incoming TLS packets. When Tomcat was configured to use NIO+OpenSSL or NIO2+OpenSSL for TLS, a specially crafted packet could be used to tr…
- CVE-2021-42340HIGHCVSS 7.5EG 7.5fixed in 10.1.0-M6, 10.0.12, 9.0.54 or 8.5.72, by version range2021-10-14
vulnerable: 8.5.60 ... 8.5.71 (10 versions)
The fix for bug 63362 present in Apache Tomcat 10.1.0-M1 to 10.1.0-M5, 10.0.0-M1 to 10.0.11, 9.0.40 to 9.0.53 and 8.5.60 to 8.5.71 introduced a memory leak. The object introduced to collect metrics for HTTP upgrade connections was not rele…
- CVE-2021-43980LOWCVSS 3.7EG 3.7fixed in 8.5.78, 9.0.62, 10.0.20 or 10.1.0-M14, by version range2022-09-28
vulnerable: 10.1.0-M1 ... 10.1.0-M8 (10 versions)
The simplified implementation of blocking reads and writes introduced in Tomcat 10 and back-ported to Tomcat 9.0.47 onwards exposed a long standing (but extremely hard to trigger) concurrency bug in Apache Tomcat 10.1.0 to 10.1.0-M12, 10.0…
- CVE-2022-23181HIGHCVSS 7.0EG 7.0fixed in 10.0.16, 9.0.58 or 8.5.75, by version range2022-01-27
vulnerable: 7.0.100 ... 8.5.9 (157 versions)
The fix for bug CVE-2020-9484 introduced a time of check, time of use vulnerability into Apache Tomcat 10.1.0-M1 to 10.1.0-M8, 10.0.0-M5 to 10.0.14, 9.0.35 to 9.0.56 and 8.5.55 to 8.5.73 that allowed a local attacker to perform actions wit…
- CVE-2022-25762HIGHCVSS 8.6EG 8.6fixed in 8.5.75 or 9.0.20, by version range2022-05-13
vulnerable: 9.0.0.M1 ... 9.0.8 (34 versions)
If a web application sends a WebSocket message concurrently with the WebSocket connection closing when running on Apache Tomcat 8.5.0 to 8.5.75 or Apache Tomcat 9.0.0.M1 to 9.0.20, it is possible that the application will continue to use t…
- CVE-2022-29885HIGHCVSS 7.5EG 8.7fixed in 10.1.0-M15, 10.0.21, 9.0.63 or 8.5.79, by version range2022-05-12
vulnerable: 8.5.38 ... 8.5.78 (35 versions)
The documentation of Apache Tomcat 10.1.0-M1 to 10.1.0-M14, 10.0.0-M1 to 10.0.20, 9.0.13 to 9.0.62 and 8.5.38 to 8.5.78 for the EncryptInterceptor incorrectly stated it enabled Tomcat clustering to run over an untrusted network. This was n…
- CVE-2022-34305MEDIUMCVSS 6.1EG 6.1fixed in 10.1.0-M17, 10.0.22, 9.0.65 or 8.5.82, by version range2022-06-23
vulnerable: 8.5.50 ... 8.5.81 (27 versions)
In Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerabil…
- CVE-2023-41080MEDIUMCVSS 6.1EG 6.1fixed in 11.0.0-M11, 10.1.13, 9.0.80 or 8.5.93, by version range2023-08-25
vulnerable: 8.5.0 ... 8.5.92 (77 versions)
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in FORM authentication feature Apache Tomcat.This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.0.12, from 9.0.0-M1 through 9.0.7…
- CVE-2023-42795MEDIUMCVSS 5.3EG 5.3fixed in 11.0.0-M12, 10.1.14, 9.0.81 or 8.5.94, by version range2023-10-10
vulnerable: 8.5.0 ... 8.5.93 (78 versions)
Incomplete Cleanup vulnerability in Apache Tomcat.When recycling various internal objects in Apache Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.80 and from 8.5.0 through 8.5.93, an er…
- CVE-2023-45648MEDIUMCVSS 5.3EG 5.3fixed in 11.0.0-M12, 10.1.14, 9.0.81 or 8.5.94, by version range2023-10-10
vulnerable: 8.5.0 ... 8.5.93 (78 versions)
Improper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A …
- CVE-2024-52318MEDIUMCVSS 6.1EG 6.1fixed in 11.0.1, 10.1.32 or 9.0.97, by version range2024-11-18
vulnerable: 9.0.96
Incorrect object recycling and reuse vulnerability in Apache Tomcat. This issue affects Apache Tomcat: 11.0.0, 10.1.31, 9.0.96. Users are recommended to upgrade to version 11.0.1, 10.1.32 or 9.0.97, which fixes the issue.
- CVE-2024-54677MEDIUMCVSS 5.3EG 5.3fixed in 11.0.2, 10.1.34 or 9.0.98, by version range2024-12-17
vulnerable: 9.0.0.M1 ... 9.0.97 (99 versions)
Uncontrolled Resource Consumption vulnerability in the examples web application provided with Apache Tomcat leads to denial of service. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.1, from 10.1.0-M1 through 10.1.33, from …
- CVE-2025-49124HIGHCVSS 8.4EG 8.4fixed in 11.0.8, 10.1.42 or 9.0.106, by version range2025-06-16
vulnerable: 9.0.100 ... 9.0.99 (68 versions)
Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.…
- CVE-2025-55752HIGHCVSS 7.5EG 8.4fixed in 11.0.11, 10.1.45 or 9.0.109, by version range2025-10-27
vulnerable: 8.5.100 ... 8.5.99 (80 versions)
Relative Path Traversal vulnerability in Apache Tomcat. The fix for bug 60013 introduced a regression where the rewritten URL was normalized before it was decoded. This introduced the possibility that, for rewrite rules that r…
- CVE-2025-55754CRITICALCVSS 9.6EG 9.6fixed in 11.0.11, 10.1.45 or 9.0.109, by version range2025-10-27
vulnerable: 8.5.100 ... 8.5.99 (37 versions)
Improper Neutralization of Escape, Meta, or Control Sequences vulnerability in Apache Tomcat. Tomcat did not escape ANSI escape sequences in log messages. If Tomcat was running in a console on a Windows operating system, and the console s…
- CVE-2025-61795MEDIUMCVSS 5.3EG 5.3fixed in 11.0.12, 10.1.47 or 9.0.110, by version range2025-10-27
vulnerable: 8.5.0 ... 8.5.99 (85 versions)
Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned u…
- CVE-2025-66614CRITICALCVSS 9.1EG 9.1fixed in 11.0.15, 10.1.50 or 9.0.113, by version range2026-02-17
vulnerable: 8.5.0 ... 8.5.99 (85 versions)
Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but…
- CVE-2026-24733LOWCVSS 3.7EG 3.79.0.113 (the fix for one version range)2026-02-17
vulnerable: 7.0.100 ... 9.0.99 (294 versions)
Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass th…
- CVE-2026-25854MEDIUMCVSS 6.1EG 6.1fixed in 9.0.116, 10.1.53 or 11.0.20, by version range2026-04-09
vulnerable: 11.0.0 ... 11.0.9 (40 versions)
Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M1 through 10.1.52, from 9.0.0.…
- CVE-2026-29129HIGHCVSS 7.5EG 7.5fixed in 9.0.116, 10.1.53 or 11.0.20, by version range2026-04-09
vulnerable: 11.0.18
Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.0.115. Users are recommended to upgrade…
- CVE-2026-29145CRITICALCVSS 9.1EG 9.1fixed in 9.0.116, 10.1.53 or 11.0.20, by version range2026-04-09
vulnerable: 11.0.0 ... 11.0.9 (40 versions)
CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.1.0-M7 thro…
- CVE-2026-29146HIGHCVSS 7.5EG 7.5fixed in 9.0.116, 10.1.53 or 11.0.20, by version range2026-04-09
vulnerable: 7.0.100 ... 7.0.109 (8 versions)
Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from 9.0.13 through 9..115, from 8.5.38 throu…
Check whether org.apache.tomcat:tomcat is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.tomcat:tomcat CVEs against the assets you own.
Book a Demo →