org.apache.tomcat:tomcat
Maven164 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.apache.tomcat:tomcatpage 4 of 4
- CVE-2026-32990MEDIUMCVSS 5.3EG 5.3fixed in 9.0.116, 10.1.53 or 11.0.20, by version range2026-04-09
vulnerable: 11.0.15, 11.0.18
Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, from 9.0.113 through 9.0.115. Users are re…
- CVE-2026-34483HIGHCVSS 7.5EG 7.5fixed in 9.0.116, 10.1.54 or 11.0.21, by version range2026-04-09
vulnerable: 11.0.0 ... 11.0.9 (41 versions)
Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 10.1.53, from 9.0.40 through 9.0.116. Us…
- CVE-2026-34486CRITICALCVSS 7.5EG 9.0⚠ KEVfixed in 11.0.21, 10.1.54 or 9.0.117, by version range2026-04-09
vulnerable: 9.0.116
Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to u…
- CVE-2026-34487HIGHCVSS 7.5EG 7.5fixed in 9.0.117, 10.1.54 or 11.0.21, by version range2026-04-09
vulnerable: 11.0.0 ... 11.0.9 (41 versions)
Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 1…
- CVE-2026-41284HIGHCVSS 7.5EG 7.5fixed in 9.0.118, 10.1.55 or 11.0.22, by version range2026-05-12
vulnerable: 11.0.0 ... 11.0.9 (42 versions)
Allocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117. Older, unsupported versi…
- CVE-2026-41293CRITICALCVSS 9.8EG 9.8fixed in 9.0.118, 10.1.55 or 11.0.22, by version range2026-05-12
vulnerable: 11.0.0 ... 11.0.9 (42 versions)
Improper Input Validation vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 10.0.0-M1 through 10.0.27. Older, end of suppo…
- CVE-2026-42498HIGHCVSS 7.3EG 7.3fixed in 9.0.118, 10.1.55 or 11.0.22, by version range2026-05-12
vulnerable: 11.0.0 ... 11.0.9 (42 versions)
Exposure of HTTP Authentication Header to unexpected hosts during WebSocket authentication vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.2 throug…
- CVE-2026-43512CRITICALCVSS 9.8EG 9.8fixed in 9.0.118, 10.1.55 or 11.0.22, by version range2026-05-12
vulnerable: 11.0.0 ... 11.0.9 (42 versions)
DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 …
- CVE-2026-43513HIGHCVSS 7.5EG 7.5fixed in 9.0.118, 10.1.55 or 11.0.22, by version range2026-05-12
vulnerable: 11.0.0 ... 11.0.9 (42 versions)
Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.…
- CVE-2026-43514LOWCVSS 3.7EG 3.7fixed in 9.0.118, 10.1.55 or 11.0.22, by version range2026-05-12
vulnerable: 11.0.0 ... 11.0.9 (42 versions)
Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8…
- CVE-2026-43515CRITICALCVSS 9.1EG 9.1fixed in 9.0.118, 10.1.55 or 11.0.22, by version range2026-05-12
vulnerable: 11.0.0 ... 11.0.9 (42 versions)
Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.…
- CVE-2026-65182CRITICALCVSS 9.1EG 9.1fixed in 11.0.25, 10.1.58 or 9.0.121, by version range2026-08-25
vulnerable: 7.0.100 ... 7.0.99 (52 versions)
Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat leads to security constraint bypass if a constraint for a longer path is specified before a more restrictive constraint for a shorter sub-path. This issue a…
- CVE-2026-65905CRITICALCVSS 9.8EG 9.8fixed in 11.0.25, 10.1.58 or 9.0.121, by version range2026-08-25
vulnerable: 7.0.100 ... 7.0.99 (52 versions)
Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize requests have been made, a client makes a DIGEST authenticated request with a nonceCount on the upper boundary of the re…
- CVE-2026-68525CRITICALCVSS 9.1EG 9.1fixed in 11.0.25, 10.1.58 or 9.0.121, by version range2026-08-25
vulnerable: 7.0.100 ... 7.0.99 (52 versions)
Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication process allows the bypassing of a security constraint that limits user has access to a resource POST but not GET. This issue affects Apache Tomcat: from 11…
Check whether org.apache.tomcat:tomcat is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.apache.tomcat:tomcat CVEs against the assets you own.
Book a Demo →