VendorsApachetomcatall versions
Vulnerabilities

Apache Tomcat

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

276CVEs
CVE-2016-6817
The HTTP/2 header parser in Apache Tomcat 9.0.0.M1 to 9.0.0.M11 and 8.5.0 to 8.5.6 entered an infinite loop if a header was received that was larger than the available buffer. This made a denial of service attack possible.
Published 2017-08-10 · Modified
7.5EPSS 0.072
CVE-2021-41079
Apache Tomcat DoS with unexpected TLS packet
Published 2021-09-16 · Modified
7.5EPSS 0.072
CVE-2016-8747
An information disclosure issue was discovered in Apache Tomcat 8.5.7 to 8.5.9 and 9.0.0.M11 to 9.0.0.M15 in reverse-proxy configurations. Http11InputBuffer.java allows remote attackers to read data that was intended to be associated with a different request.
Published 2017-03-14 · Analyzed
7.5EPSS 0.071
CVE-2021-30639
DoS after non-blocking IO error
Published 2021-07-12 · Modified
7.5EPSS 0.069
CVE-2026-34486
Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor
Published 2026-04-09 · Analyzed
7.5KEVEPSS 0.066
CVE-2002-1394
Apache Tomcat 4.0.5 and earlier, when using both the invoker servlet and the default servlet, allows remote attackers to read source code for server files or bypass certain protections, a variant of CAN-2002-1148.
Published 2004-09-01 · Modified
7.5EPSS 0.059
CVE-2001-1563
Unknown vulnerability in Tomcat 3.2.1 running on HP Secure OS for Linux 1.0 allows attackers to access servlet resources. NOTE: due to the vagueness of the vendor advisory, it is not clear whether this issue is already covered by other CVE identifiers.
Published 2005-07-14 · Modified
7.5EPSS 0.049
CVE-2024-34750
Apache Tomcat: HTTP/2 excess header handling DoS
Published 2024-07-03 · Modified
7.5EPSS 0.046
CVE-2002-0493
Apache Tomcat may be started without proper security settings if errors are encountered while reading the web.xml file, which could allow attackers to bypass intended restrictions.
Published 2003-04-02 · Modified
7.5EPSS 0.038
CVE-2025-48989
Apache Tomcat: h2 DoS - Made You Reset
Published 2025-08-13 · Modified
7.5EPSS 0.037
CVE-2025-49125
Apache Tomcat: Security constraint bypass for pre/post-resources
Published 2025-06-16 · Modified
7.5EPSS 0.034
CVE-2026-29146
Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default
Published 2026-04-09 · Modified
7.5EPSS 0.029
CVE-2023-46589
Apache Tomcat: HTTP request smuggling via malformed trailer headers
Published 2023-11-28 · Modified
7.5EPSS 0.027
CVE-2022-45143
Apache Tomcat: JsonErrorReportValve escaping
Published 2023-01-03 · Modified
7.5EPSS 0.025
CVE-2025-52520
Apache Tomcat: DoS via integer overflow in multipart file upload
Published 2025-07-10 · Modified
7.5EPSS 0.021
CVE-2025-53506
Apache Tomcat: DoS via excessive h2 streams at connection start
Published 2025-07-10 · Modified
7.5EPSS 0.020
CVE-2025-52434
Apache Tomcat: APR/Native Connector crash leading to DoS
Published 2025-07-10 · Modified
7.5EPSS 0.019
CVE-2022-42252
Apache Tomcat request smuggling via malformed content-length
Published 2022-11-01 · Modified
7.5EPSS 0.015
CVE-2023-34981
Apache Tomcat: AJP response header mix-up
Published 2023-06-21 · Modified
7.5EPSS 0.011
CVE-2026-41284
Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling
Published 2026-05-12 · Analyzed
7.5EPSS 0.009
CVE-2026-66299
Apache Tomcat: DoS via WebSocket chat example
Published 2026-07-28 · Analyzed
7.5EPSS 0.007
CVE-2026-65927
Apache Tomcat: RewriteValve [N] restarts at the second rule and may bypass access control
Published 2026-08-25 · Analyzed
7.5EPSS 0.007
CVE-2026-68763
Apache Tomcat: DoS via allocation leak in HTTP/2 backlog tracking when a stream is reset
Published 2026-08-25 · Analyzed
7.5EPSS 0.007
CVE-2026-43513
Apache Tomcat: LockOutRealm treats user names as case-sensitive
Published 2026-05-12 · Analyzed
7.5EPSS 0.007
CVE-2026-24880
Apache Tomcat: Request smuggling via invalid chunk extension
Published 2026-04-09 · Analyzed
7.5EPSS 0.007
CVE-2026-34487
Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer token
Published 2026-04-09 · Analyzed
7.5EPSS 0.006
CVE-2026-34483
Apache Tomcat: Incomplete escaping of JSON access logs
Published 2026-04-09 · Analyzed
7.5EPSS 0.006
CVE-2026-24734
Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass
Published 2026-02-17 · Modified
7.5EPSS 0.005
CVE-2026-29129
Apache Tomcat: TLS cipher order is not preserved
Published 2026-04-09 · Analyzed
7.5EPSS 0.004
CVE-2025-46701
Apache Tomcat: Security constraint bypass for CGI scripts
Published 2025-05-29 · Modified
7.3EPSS 0.029
CVE-2026-55957
Apache Tomcat: Authentication bypass with JNDIRealm and GSSAPI authenticated bind
Published 2026-06-29 · Analyzed
7.3EPSS 0.008
CVE-2026-42498
Apache Tomcat: WebSocket authentication header exposure
Published 2026-05-12 · Analyzed
7.3EPSS 0.007
CVE-2026-53404
Apache Tomcat: Bad ornext processing in RewriteValve
Published 2026-06-29 · Analyzed
7.3EPSS 0.007
CVE-2016-6816
The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters. This could be exploited, in conjunction with a proxy that also permitted the invalid characters but with a different interpretation, to inject data into the HTTP response. By manipulating the HTTP response the attacker could poison a web-cache, perform an XSS attack and/or obtain sensitive information from requests other then their own.
Published 2017-03-20 · Modified
7.11 PoCEPSS 0.396
CVE-2020-9484
When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassNameFilter="null" (the default unless a SecurityManager is used) or a sufficiently lax filter to allow the attacker provided object to be deserialized; and d) the attacker knows the relative file path from the storage location used by FileStore to the file the attacker has control over; then, using a specifically crafted request, the attacker will be able to trigger remote code execution via deserialization of the file under their control. Note that all of conditions a) to d) must be true for the attack to succeed.
Published 2020-05-20 · Modified
7.0EPSS 0.555
CVE-2021-25329
Incomplete fix for CVE-2020-9484
Published 2021-03-01 · Modified
7.0EPSS 0.095
CVE-2019-12418
When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration files is able to manipulate the RMI registry to perform a man-in-the-middle attack to capture user names and passwords used to access the JMX interface. The attacker can then use these credentials to access the JMX interface and gain complete control over the Tomcat instance.
Published 2019-12-23 · Modified
7.0EPSS 0.012
CVE-2022-23181
Local privilege escalation with FileStore
Published 2022-01-27 · Modified
7.0EPSS 0.007
CVE-2002-1567
Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1 allows remote attackers to execute arbitrary web script and steal cookies via a URL with encoded newlines followed by a request to a .jsp file whose name contains the script.
Published 2003-09-19 · Modified
6.81 PoCEPSS 0.271
CVE-2013-4444
Unrestricted file upload vulnerability in Apache Tomcat 7.x before 7.0.40, in certain situations involving outdated java.io.File code and a custom JMX configuration, allows remote attackers to execute arbitrary code by uploading and accessing a JSP file.
Published 2014-09-12 · Modified
6.8EPSS 0.140
← Prev3 / 7Next →