apache Vulnerabilities and Affected Products
Vulnerabilities associated with Tomcat.
Products
Clear product- HTTP Server21 vulnerabilities
- OFBiz21 vulnerabilities
- Struts18 vulnerabilities
- inlong17 vulnerabilities
- Tomcat16 vulnerabilities
- airflow15 vulnerabilities
- Solr10 vulnerabilities
- traffic_server8 vulnerabilities
- ActiveMQ7 vulnerabilities
- linkis7 vulnerabilities
- cloudstack6 vulnerabilities
- cxf6 vulnerabilities
- dolphinscheduler6 vulnerabilities
- hertzbeat6 vulnerabilities
- http_server6 vulnerabilities
- pulsar6 vulnerabilities
- streampark6 vulnerabilities
- zeppelin6 vulnerabilities
- Apache HTTP Server5 vulnerabilities
- Apache Tomcat5 vulnerabilities
- kafka5 vulnerabilities
- ambari4 vulnerabilities
- Apache OFBiz4 vulnerabilities
- Apache Tika4 vulnerabilities
- camel4 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-34486HIGH | Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptorMissing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to version 11.0.21, 10.1.54 or 9.0.117, which fix the issue. | CVSS7.5v3.1 | EPSS82.9% | PoCs6 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUTPath Equivalence: 'file.Name' (Internal Dot) leading to Remote Code Execution and/or Information disclosure and/or malicious content added to uploaded files via write enabled Default Servlet in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.2, from 10.1.0-M1 through 10.1.34, from 9.0.0.M1 through 9.0.98. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affect… | CVSS-v4.0 | EPSS>99.9% | PoCs48 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX | |
CVE-2024-52317MEDIUM | Apache Tomcat: Request/response mix-up with HTTP/2Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between users. This issue affects Apache Tomcat: from 11.0.0-M23 through 11.0.0-M26, from 10.1.27 through 10.1.30, from 9.0.92 through 9.0.95. Users are recommended to upgrade to version 11.0.0, 10.1.31 or 9.0.96, which fixes the issue. CWE-326Nov 18, 2024 | CVSS6.5v3.1 | EPSS2.03% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2024-52316CRITICAL | Apache Tomcat: Authentication bypass when using Jakarta Authentication APIUnchecked Error Condition vulnerability in Apache Tomcat. If Tomcat is configured to use a custom Jakarta Authentication (formerly JASPIC) ServerAuthContext component which may throw an exception during the authentication process without explicitly setting an HTTP status to indicate failure, the authentication may not fail, allowing the user to bypass the authentication process. There are no known Jakarta Authentication components that behave in this way. This issue affects Apache Tomcat: from … | CVSS9.8v3.1 | EPSS6.29% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Apache Tomcat: Denial of ServiceAllocation of Resources Without Limits or Throttling vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24, from 9.0.13 through 9.0.89. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.35 through 8.5.100 and 7.0.92 through 7.0.109. Other EOL versions may also be affected. Users are recommended to upgrade to version 11.0.0-M21, 10.1.25, or 9.0.90, which fixes the is… CWE-770Nov 7, 2024 | CVSS-v4.0 | EPSS1.7% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
Apache Tomcat: HTTP/2 excess header handling DoSImproper Handling of Exceptional Conditions, Uncontrolled Resource Consumption vulnerability in Apache Tomcat. When processing an HTTP/2 stream, Tomcat did not handle some cases of excessive HTTP headers correctly. This led to a miscounting of active HTTP/2 streams which in turn led to the use of an incorrect infinite timeout which allowed connections to remain open which should have been closed. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.0-M20, from 10.1.0-M1 through 10.1.24… | CVSS-v4.0 | EPSS4.6% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX | |
CVE-2023-46589HIGH | Apache Tomcat: HTTP request smuggling via malformed trailer headersImproper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M10, from 10.1.0-M1 through 10.1.15, from 9.0.0-M1 through 9.0.82 and from 8.5.0 through 8.5.95 did not correctly parse HTTP trailer headers. A trailer header that exceeded the header size limit could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommende… | CVSS7.5v3.1 | EPSS2.65% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-45648MEDIUM | Apache Tomcat: Trailer header parsing too lenientImproper Input Validation vulnerability in Apache Tomcat.Tomcat from 11.0.0-M1 through 11.0.0-M11, from 10.1.0-M1 through 10.1.13, from 9.0.0-M1 through 9.0.81 and from 8.5.0 through 8.5.93 did not correctly parse HTTP trailer headers. A specially crafted, invalid trailer header could cause Tomcat to treat a single request as multiple requests leading to the possibility of request smuggling when behind a reverse proxy. Older, EOL versions may also be affected. Users are recommended to upgr… | CVSS5.3v3.1 | EPSS5.85% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2023-34981HIGH | Apache Tomcat: AJP response header mix-upA regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for the response which in turn meant that at least one AJP proxy (mod_proxy_ajp) would use the response headers from the previous request leading to an information leak. CWE-732Jun 21, 2023 | CVSS7.5v3.1 | EPSS1.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-34305MEDIUM | XSS in examples web applicationIn Apache Tomcat 10.1.0-M1 to 10.1.0-M16, 10.0.0-M1 to 10.0.22, 9.0.30 to 9.0.64 and 8.5.50 to 8.5.81 the Form authentication example in the examples web application displayed user provided data without filtering, exposing a XSS vulnerability. | CVSS6.1v3.1 | EPSS6.16% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2020-1938CRITICAL | Improper Privilege Management in TomcatWhen using the Apache JServ Protocol (AJP), care must be taken when trusting incoming connections to Apache Tomcat. Tomcat treats AJP connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploited in ways that may be surprising. In Apache Tomcat 9.0.0.M1 to 9.0.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99, Tomcat shipped with an AJP Connector enabled by default that listened on all configured IP addresses. It … | CVSS9.8v3.1 | EPSS99.3% | PoCs44 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2019-0232HIGH | Apache Tomcat OS Command Injection vulnerabilityWhen running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a bug in the way the JRE passes command line arguments to Windows. The CGI Servlet is disabled by default. The CGI option enableCmdLineArguments is disable by default in Tomcat 9.0.x (and will be disabled by default in all versions in response to this vulnerability). For a detailed explanation of the JR… | CVSS8.1v3.0 | EPSS99.7% | PoCs14 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2018-11759HIGH | Apache Tomcat Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')The Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat JK (mod_jk) Connector 1.2.0 to 1.2.44 did not handle some edge cases correctly. If only a sub-set of the URLs supported by Tomcat were exposed via httpd, then it was possible for a specially constructed request to expose application functionality through the reverse proxy that was not intended for clients accessing the application via the reverse proxy. It was … | CVSS7.5v3.0 | EPSS90.6% | PoCs3 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2017-12617HIGH | Unrestricted Upload of File with Dangerous Type Apache TomcatWhen running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. | CVSS8.1v3.1 | EPSS>99.9% | PoCs14 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |
CVE-2017-12615HIGH | When running Apache Tomcat on Windows with HTTP PUTs enabled it was possible to upload a JSP file to the serverWhen running Apache Tomcat 7.0.0 to 7.0.79 on Windows with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the server. | CVSS8.1v3.1 | EPSS99.6% | PoCs19 | SignalsListed in CISA KEVKnown ransomware use1 Nuclei template | STIX |
CVE-2016-8735CRITICAL | Apache Tomcat Improper Access Control vulnerabilityRemote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential types. | CVSS9.8v3.1 | EPSS90.3% | PoCs0 | SignalsListed in CISA KEVNo known ransomware use1 Nuclei template | STIX |