VendorsApachetomcatany version
Vulnerabilities

Apache Tomcat any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

149CVEs
CVE-2019-0199
The HTTP/2 implementation in Apache Tomcat 9.0.0.M1 to 9.0.14 and 8.5.0 to 8.5.37 accepted streams with excessive numbers of SETTINGS frames and also permitted clients to keep streams open without reading/writing request/response data. By keeping streams open for requests that utilised the Servlet API's blocking I/O, clients were able to cause server-side threads to block eventually leading to thread exhaustion and a DoS.
Published 2019-04-10 · Modified
7.5EPSS 0.729
CVE-2025-55752
Apache Tomcat: Directory traversal via rewrite with possible RCE if PUT is enabled
Published 2025-10-27 · Modified
7.5EPSS 0.665
CVE-2020-13934
An h2c direct connection to Apache Tomcat 10.0.0-M1 to 10.0.0-M6, 9.0.0.M5 to 9.0.36 and 8.5.1 to 8.5.56 did not release the HTTP/1.1 processor after the upgrade to HTTP/2. If a sufficient number of such requests were made, an OutOfMemoryException could occur leading to a denial of service.
Published 2020-07-14 · Modified
7.5EPSS 0.641
CVE-2025-31650
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
Published 2025-04-28 · Modified
7.51 PoCEPSS 0.599
CVE-2023-28709
Apache Tomcat: Fix for CVE-2023-24998 is incomplete
Published 2023-05-22 · Modified
7.5EPSS 0.480
CVE-2025-48988
Apache Tomcat: FileUpload large number of parts with headers DoS
Published 2025-06-16 · Modified
7.5EPSS 0.305
CVE-2020-11996
A specially crafted sequence of HTTP/2 requests sent to Apache Tomcat 10.0.0-M1 to 10.0.0-M5, 9.0.0.M1 to 9.0.35 and 8.5.0 to 8.5.55 could trigger high CPU usage for several seconds. If a sufficient number of such requests were made on concurrent HTTP/2 connections, the server could become unresponsive.
Published 2020-06-26 · Modified
7.5EPSS 0.267
CVE-2020-17527
Apache Tomcat: Request header mix-up between HTTP/2 streams
Published 2020-12-03 · Modified
7.5EPSS 0.246
CVE-2024-24549
Apache Tomcat: HTTP/2 header handling DoS
Published 2024-03-13 · Modified
7.5EPSS 0.231
CVE-2018-8034
The host name verification when using TLS with the WebSocket client was missing. It is now enabled by default. Versions Affected: Apache Tomcat 9.0.0.M1 to 9.0.9, 8.5.0 to 8.5.31, 8.0.0.RC1 to 8.0.52, and 7.0.35 to 7.0.88.
Published 2018-08-01 · Modified
7.5EPSS 0.213
CVE-2018-1336
An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.7, 8.5.0 to 8.5.30, 8.0.0.RC1 to 8.0.51, and 7.0.28 to 7.0.86.
Published 2018-08-02 · Modified
7.5EPSS 0.206
CVE-2021-25122
Apache Tomcat h2c request mix-up
Published 2021-03-01 · Modified
7.5EPSS 0.181
CVE-2021-42340
DoS via memory leak with WebSocket connections
Published 2021-10-14 · Modified
7.5EPSS 0.118
CVE-2019-17563
When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The window was considered too narrow for an exploit to be practical but, erring on the side of caution, this issue has been treated as a security vulnerability.
Published 2019-12-23 · Modified
7.5EPSS 0.107
CVE-2026-29146
Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
Published 2026-04-09 · Modified
7.5EPSS 0.089
CVE-2016-6796
A malicious web application running on Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 was able to bypass a configured SecurityManager via manipulation of the configuration parameters for the JSP Servlet.
Published 2017-08-11 · Modified
7.5EPSS 0.083
CVE-2016-6797
The ResourceLinkFactory implementation in Apache Tomcat 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not limit web application access to global JNDI resources to those resources explicitly linked to the web application. Therefore, it was possible for a web application to access any global JNDI resource whether an explicit ResourceLink had been configured or not.
Published 2017-08-10 · Modified
7.5EPSS 0.081
CVE-2013-2185
The readObject method in the DiskFileItem class in Apache Tomcat and JBoss Web, as used in Red Hat JBoss Enterprise Application Platform 6.1.0 and Red Hat JBoss Portal 6.0.0, allows remote attackers to write to arbitrary files via a NULL byte in a file name in a serialized instance, a similar issue to CVE-2013-2186. NOTE: this issue is reportedly disputed by the Apache Tomcat team, although Red Hat considers it a vulnerability. The dispute appears to regard whether it is the responsibility of applications to avoid providing untrusted data to be deserialized, or whether this class should inherently protect against this issue
Published 2014-01-19 · Modified
7.5EPSS 0.072
CVE-2021-41079
Apache Tomcat DoS with unexpected TLS packet
Published 2021-09-16 · Modified
7.5EPSS 0.072
CVE-2016-8747
An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request.
Published 2017-03-14 · Analyzed
7.5EPSS 0.071
CVE-2024-34750
Apache Tomcat: HTTP/2 excess header handling DoS
Published 2024-07-03 · Modified
7.5EPSS 0.046
CVE-2002-0493
Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.
Published 2003-04-02 · Modified
7.5EPSS 0.038
CVE-2025-48989
Apache Tomcat: h2 DoS - Made You Reset
Published 2025-08-13 · Modified
7.5EPSS 0.037
CVE-2025-49125
Apache Tomcat: Security constraint bypass for pre/post-resources
Published 2025-06-16 · Modified
7.5EPSS 0.034
CVE-2023-46589
Apache Tomcat: HTTP request smuggling via malformed trailer headers
Published 2023-11-28 · Modified
7.5EPSS 0.027
CVE-2022-45143
Apache Tomcat: JsonErrorReportValve escaping
Published 2023-01-03 · Modified
7.5EPSS 0.025
CVE-2025-52520
Apache Tomcat: DoS via integer overflow in multipart file upload
Published 2025-07-10 · Modified
7.5EPSS 0.021
CVE-2025-53506
Apache Tomcat: DoS via excessive h2 streams at connection start
Published 2025-07-10 · Modified
7.5EPSS 0.020
CVE-2025-52434
Apache Tomcat: APR/Native Connector crash leading to DoS
Published 2025-07-10 · Modified
7.5EPSS 0.019
CVE-2022-42252
Apache Tomcat request smuggling via malformed content-length
Published 2022-11-01 · Modified
7.5EPSS 0.015
CVE-2026-41284
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
Published 2026-05-12 · Analyzed
7.5EPSS 0.008
CVE-2026-68763
Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset
Published 2026-08-25 · Analyzed
7.5EPSS 0.008
CVE-2026-65927
Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control
Published 2026-08-25 · Analyzed
7.5EPSS 0.008
CVE-2026-66299
Apache Tomcat: DoS via WebSocket chat example
Published 2026-07-28 · Analyzed
7.5EPSS 0.005
CVE-2026-24880
Apache Tomcat: Request smuggling via invalid chunk extension
Published 2026-04-09 · Analyzed
7.5EPSS 0.005
CVE-2026-24734
Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass
Published 2026-02-17 · Modified
7.5EPSS 0.005
CVE-2026-43513
Apache Tomcat: LockOutRealm treats user names as case-sensitive
Published 2026-05-12 · Analyzed
7.5EPSS 0.005
CVE-2026-34483
Apache Tomcat: Incomplete escaping of JSON access logs
Published 2026-04-09 · Analyzed
7.5EPSS 0.005
CVE-2026-34487
Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token
Published 2026-04-09 · Analyzed
7.5EPSS 0.004
CVE-2026-29129
Apache Tomcat: TLS cipher order is not preserved
Published 2026-04-09 · Analyzed
7.5EPSS 0.003
← Prev2 / 4Next →