VendorsApachetomcatall versions
Vulnerabilities

Apache Tomcat

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

276CVEs
CVE-2003-0044
Multiple cross-site scripting (XSS) vulnerabilities in the (1) examples and (2) ROOT web applications for Jakarta Tomcat 3.x through 3.3.1a allow remote attackers to insert arbitrary web script or HTML.
Published 2003-01-29 · Modified
6.8EPSS 0.091
CVE-2013-2067
java/org/apache/catalina/authenticator/FormAuthenticator.java in the form authentication feature in Apache Tomcat 6.0.21 through 6.0.36 and 7.x before 7.0.33 does not properly handle the relationships between authentication requirements and sessions, which allows remote attackers to inject a request into a session by sending this request during completion of the login form, a variant of a session fixation attack.
Published 2013-06-01 · Modified
6.8EPSS 0.071
CVE-2013-6357
Cross-site request forgery (CSRF) vulnerability in the Manager application in Apache Tomcat 5.5.25 and earlier allows remote attackers to hijack the authentication of administrators for requests that manipulate application deployment via the POST method, as demonstrated by a /manager/html/undeploy?path= URI. NOTE: the vendor disputes the significance of this report, stating that "the Apache Tomcat Security team has not accepted any reports of CSRF attacks against the Manager application ... as they require a reckless system administrator.
Published 2013-11-13 · Modified
6.81 PoCEPSS 0.025
CVE-2026-73180
Apache Tomcat: Authenticated WebSocket session survives end of HTTP session
Published 2026-08-25 · Analyzed
6.8EPSS 0.004
CVE-2018-1305
Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. Because security constraints defined in this way apply to the URL pattern and any URLs below that point, it was possible - depending on the order Servlets were loaded - for some security constraints not to be applied. This could have exposed resources to users who were not authorised to access them.
Published 2018-02-23 · Modified
6.5EPSS 0.145
CVE-2016-0763
The setGlobalContext method in org/apache/naming/factory/ResourceLinkFactory.java in Apache Tomcat 7.x before 7.0.68, 8.x before 8.0.31, and 9.x before 9.0.0.M3 does not consider whether ResourceLinkFactory.setGlobalContext callers are authorized, which allows remote authenticated users to bypass intended SecurityManager restrictions and read or write to arbitrary application data, or cause a denial of service (application disruption), via a web application that sets a crafted global context.
Published 2016-02-25 · Modified
6.5EPSS 0.113
CVE-2021-30640
Auth weakness in JNDIRealm
Published 2021-07-12 · Modified
6.5EPSS 0.099
CVE-2024-52317
Apache Tomcat: Request/response mix-up with HTTP/2
Published 2024-11-18 · Analyzed
6.5EPSS 0.021
CVE-2025-55668
Apache Tomcat: session fixation via rewrite valve
Published 2025-08-13 · Modified
6.5EPSS 0.009
CVE-2026-55956
Apache Tomcat: Security constraints for default servlet ignored method
Published 2026-06-29 · Analyzed
6.5EPSS 0.007
CVE-2026-34500
Apache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Published 2026-04-09 · Analyzed
6.5EPSS 0.006
CVE-2026-24733
Apache Tomcat: Security constraint bypass with HTTP/0.9
Published 2026-02-17 · Modified
6.5EPSS 0.005
CVE-2026-55955
Apache Tomcat: EncryptInterceptor not protected against replay attacks
Published 2026-06-29 · Analyzed
6.5EPSS 0.004
CVE-2000-0760
The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker requests a nonexistent URL with a .snp extension.
Published 2000-09-21 · Modified
6.41 PoCEPSS 0.625
CVE-2010-2227
Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-Encoding header, which allows remote attackers to cause a denial of service (application outage) or obtain sensitive information via a crafted header that interferes with "recycling of a buffer."
Published 2010-07-13 · Modified
6.4EPSS 0.548
CVE-2000-0759
Jakarta Tomcat 3.1 under Apache reveals physical path information when a remote attacker requests a URL that does not exist, which generates an error message that includes the physical path.
Published 2000-09-21 · Modified
6.41 PoCEPSS 0.257
CVE-2014-0227
java/org/apache/coyote/http11/filters/ChunkedInputFilter.java in Apache Tomcat 6.x before 6.0.42, 7.x before 7.0.55, and 8.x before 8.0.9 does not properly handle attempts to continue reading data after an error has occurred, which allows remote attackers to conduct HTTP request smuggling attacks or cause a denial of service (resource consumption) by streaming data with malformed chunked transfer coding.
Published 2015-02-16 · Modified
6.4EPSS 0.210
CVE-2007-5342
The default catalina.policy in the JULI logging component in Apache Tomcat 5.5.9 through 5.5.25 and 6.0.0 through 6.0.15 does not restrict certain permissions for web applications, which allows attackers to modify logging configuration options and overwrite arbitrary files, as demonstrated by changing the (1) level, (2) directory, and (3) prefix attributes in the org.apache.juli.FileHandler handler.
Published 2007-12-27 · Modified
6.4EPSS 0.052
CVE-2010-4312
The default configuration of Apache Tomcat 6.x does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to hijack a session via script access to a cookie.
Published 2010-11-26 · Modified
6.4EPSS 0.021
CVE-2024-23672
Apache Tomcat: WebSocket DoS with incomplete closing handshake
Published 2024-03-13 · Modified
6.3EPSS 0.023
CVE-2019-0221
The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by default. The printenv command is intended for debugging and is unlikely to be present in a production website.
Published 2019-05-28 · Modified
6.11 PoCEPSS 0.592
CVE-2022-34305
XSS in examples web application
Published 2022-06-23 · Modified
6.1EPSS 0.067
CVE-2023-41080
Apache Tomcat: Open redirect with FORM authentication
Published 2023-08-25 · Modified
6.1EPSS 0.060
CVE-2026-50229
Apache Tomcat: XSS in number guess example
Published 2026-06-29 · Analyzed
6.1EPSS 0.041
CVE-2024-52318
Apache Tomcat: Incorrect JSP tag recycling leads to XSS
Published 2024-11-18 · Analyzed
6.1EPSS 0.017
CVE-2026-25854
Apache Tomcat: Occasionally open redirect
Published 2026-04-09 · Analyzed
6.1EPSS 0.005
CVE-2019-2684
Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 7u211, 8u202, 11.0.2 and 12; Java SE Embedded: 8u201. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE, Java SE Embedded. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java SE, Java SE Embedded accessible data. Note: This vulnerability applies to Java deployments, typically in clients running sandboxed Java Web Start applications or sandboxed Java applets (in Java SE 8), that load and run untrusted code (e.g., code that comes from the internet) and rely on the Java sandbox for security. This vulnerability can also be exploited by using APIs in the specified Component, e.g., through a web service which supplies data to the APIs. CVSS 3.0 Base Score 5.9 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N).
Published 2019-04-23 · Modified
5.9EPSS 0.376
CVE-2021-24122
Apache Tomcat information disclosure
Published 2021-01-14 · Modified
5.9EPSS 0.229
CVE-2018-1304
The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 when used as part of a security constraint definition. This caused the constraint to be ignored. It was, therefore, possible for unauthorised users to gain access to web application resources that should have been protected. Only security constraints with a URL pattern of the empty string were affected.
Published 2018-02-28 · Modified
5.9EPSS 0.171
CVE-2018-8037
If an async request was completed by the application at the same time as the container triggered the async timeout, a race condition existed that could result in a user seeing a response intended for a different user. An additional issue was present in the NIO and NIO2 connectors that did not correctly track the closure of the connection when an async request was completed by the application and timed out by the container at the same time. This could also result in a user seeing a response intended for another user. Versions Affected: Apache Tomcat 9.0.0.M9 to 9.0.9 and 8.5.5 to 8.5.31.
Published 2018-08-02 · Modified
5.9EPSS 0.113
CVE-2016-0762
The Realm implementations in Apache Tomcat versions 9.0.0.M1 to 9.0.0.M9, 8.5.0 to 8.5.4, 8.0.0.RC1 to 8.0.36, 7.0.0 to 7.0.70 and 6.0.0 to 6.0.45 did not process the supplied password if the supplied user name did not exist. This made a timing attack possible to determine valid user names. Note that the default configuration includes the LockOutRealm which makes exploitation of this vulnerability harder.
Published 2017-08-10 · Modified
5.9EPSS 0.080
CVE-2023-42794
Apache Tomcat: FileUpload: DoS due to accumulation of temporary files on Windows
Published 2023-10-10 · Modified
5.9EPSS 0.019
CVE-2013-4286
Apache Tomcat before 6.0.39, 7.x before 7.0.47, and 8.x before 8.0.0-RC3, when an HTTP connector or AJP connector is used, does not properly handle certain inconsistent HTTP request headers, which allows remote attackers to trigger incorrect identification of a request's length and conduct request-smuggling attacks via (1) multiple Content-Length headers or (2) a Content-Length header and a "Transfer-Encoding: chunked" header. NOTE: this vulnerability exists because of an incomplete fix for CVE-2005-2090.
Published 2014-02-26 · Modified
5.8EPSS 0.168
CVE-2009-2693
Directory traversal vulnerability in Apache Tomcat 5.5.0 through 5.5.28 and 6.0.0 through 6.0.20 allows remote attackers to create or overwrite arbitrary files via a .. (dot dot) in an entry in a WAR file, as demonstrated by a ../../bin/catalina.bat entry.
Published 2010-01-28 · Modified
5.8EPSS 0.096
CVE-2020-1935
In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as valid. This led to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
Published 2020-02-24 · Modified
5.8EPSS 0.094
CVE-2019-17569
The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were incorrectly processed leading to a possibility of HTTP Request Smuggling if Tomcat was located behind a reverse proxy that incorrectly handled the invalid Transfer-Encoding header in a particular manner. Such a reverse proxy is considered unlikely.
Published 2020-02-24 · Modified
5.8EPSS 0.089
CVE-2011-1419
Apache Tomcat 7.x before 7.0.11, when web.xml has no security constraints, does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application. NOTE: this vulnerability exists because of an incomplete fix for CVE-2011-1088.
Published 2011-03-14 · Modified
5.8EPSS 0.065
CVE-2011-1088
Apache Tomcat 7.x before 7.0.10 does not follow ServletSecurity annotations, which allows remote attackers to bypass intended access restrictions via HTTP requests to a web application.
Published 2011-03-14 · Modified
5.8EPSS 0.065
CVE-2011-1183
Apache Tomcat 7.0.11, when web.xml has no login configuration, does not follow security constraints, which allows remote attackers to bypass intended access restrictions via HTTP requests to a meta-data complete web application. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1088 and CVE-2011-1419.
Published 2011-04-08 · Modified
5.8EPSS 0.062
CVE-2008-0002
Apache Tomcat 6.0.0 through 6.0.15 processes parameters in the context of the wrong request when an exception occurs during parameter processing, which might allow remote attackers to obtain sensitive information, as demonstrated by disconnecting during this processing in order to trigger the exception.
Published 2008-02-12 · Modified
5.8EPSS 0.050
← Prev4 / 7Next →