← apache

apache / tomcat

26 known vulnerabilities in apache tomcat.

CVEPriorityEPSSCVSSKEVWhat
CVE-2017-12617 Act now 100.0% 8.1 When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC…
CVE-2017-12615 Act now 99.6% 8.1 When running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.…
CVE-2020-1938 Act now 99.3% 9.8 When using the Apache JServ Protocol (AJP), care must be taken when trusting inc…
CVE-2026-34486 Act now 98.6% 7.5 Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the f…
CVE-2016-8735 Act now 90.3% 9.8 Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7…
CVE-2020-13935 High 86.6% 7.5 The payload length in a WebSocket frame was not correctly validated in Apache To…
CVE-2021-33037 High 75.4% 5.3 Apache Tomcat 10.0.0-M1 to 10.0.6, 9.0.0.M1 to 9.0.46 and 8.5.0 to 8.5.66 did no…
CVE-2020-13934 High 64.1% 7.5 An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.…
CVE-2020-9484 High 56.6% 7.0 When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.…
CVE-2021-24122 Medium 22.9% 5.9 When serving resources from a network location using the NTFS file system, Apach…
CVE-2021-25122 Medium 18.1% 7.5 When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1…
CVE-2021-25329 Medium 9.5% 7.0 The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to …
CVE-2026-29146 Medium 8.9% 7.5 Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default …
CVE-2022-25762 Medium 8.4% 8.6 If a web application sends a WebSocket message concurrently with the WebSocket c…
CVE-2026-68763 Medium 0.8% 7.5 Uncontrolled Resource Consumption vulnerability in Apache Tomcat via an allocati…
CVE-2026-65927 Medium 0.8% 7.5 Off-by-one Error vulnerability in Apache Tomcat impacting the [N] flag on the re…
CVE-2026-65905 Medium 0.8% 9.8 Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST …
CVE-2026-65637 Medium 0.8% 9.8 Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix f…
CVE-2026-68525 Medium 0.6% 9.1 Incorrect Authorization vulnerability in Apache Tomcat's FORM authentication pro…
CVE-2026-65182 Medium 0.6% 9.1 Improper Access Control, Incorrect Authorization vulnerability in Apache Tomcat …
CVE-2026-66422 Medium 0.6% 8.1 Improper Authorization vulnerability in Apache Tomcat cause by security-role-ref…
CVE-2026-68569 Medium 0.5% 8.1 Improper Authentication vulnerability in Apache Tomcat meant that in some circum…
CVE-2026-65183 Medium 0.5% 8.1 Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in Apache Tomcat…
CVE-2019-17569 Low 8.9% 4.8 The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and …
CVE-2026-73180 Low 0.5% 6.8 Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the…
CVE-2026-66299 Low 0.5% 5.3 Uncontrolled Resource Consumption vulnerability in Apache Tomcat's WebSocket cha…