VendorsApachetomcat10.1.0
Vulnerabilities

Apache Tomcat 10.1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

13CVEs
CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Published 2025-03-10 · Analyzed
10.0KEV1 PoCEPSS 0.999
CVE-2026-29145
Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail is disabled
Published 2026-04-09 · Analyzed
9.1EPSS 0.006
CVE-2025-66614
Apache Tomcat: Client certificate verification bypass due to virtual host mapping
Published 2026-02-17 · Modified
9.1EPSS 0.002
CVE-2024-38286
Apache Tomcat: Denial of Service
Published 2024-11-07 · Modified
8.6EPSS 0.017
CVE-2022-29885
EncryptInterceptor does not provide complete protection on insecure networks
Published 2022-05-12 · Modified
7.51 PoCEPSS 0.735
CVE-2021-42340
DoS via memory leak with WebSocket connections
Published 2021-10-14 · Modified
7.5EPSS 0.118
CVE-2022-45143
Apache Tomcat: JsonErrorReportValve escaping
Published 2023-01-03 · Modified
7.5EPSS 0.025
CVE-2026-24734
Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass
Published 2026-02-17 · Modified
7.5EPSS 0.005
CVE-2022-23181
Local privilege escalation with FileStore
Published 2022-01-27 · Modified
7.0EPSS 0.007
CVE-2022-34305
XSS in examples web application
Published 2022-06-23 · Modified
6.1EPSS 0.067
CVE-2023-45648
Apache Tomcat: Trailer header parsing too lenient
Published 2023-10-10 · Modified
5.3EPSS 0.058
CVE-2023-42795
Apache Tomcat: Failure during request clean-up leads to sensitive data leaking to subsequent requests
Published 2023-10-10 · Modified
5.3EPSS 0.022
CVE-2021-43980
Apache Tomcat: Information disclosure
Published 2022-09-28 · Modified
3.7EPSS 0.019