VendorsApachetomcat11.0.0
Vulnerabilities

Apache Tomcat 11.0.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

22CVEs
CVE-2025-24813
Apache Tomcat: Potential RCE and/or information disclosure and/or information corruption with partial PUT
Published 2025-03-10 · Analyzed
10.0KEV1 PoCEPSS 0.999
CVE-2024-52316
Apache Tomcat: Authentication bypass when using Jakarta Authentication API
Published 2024-11-18 · Analyzed
9.8EPSS 0.062
CVE-2025-66614
Apache Tomcat: Client certificate verification bypass due to virtual host mapping
Published 2026-02-17 · Modified
9.1EPSS 0.002
CVE-2024-38286
Apache Tomcat: Denial of Service
Published 2024-11-07 · Modified
8.6EPSS 0.017
CVE-2023-44487
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
Published 2023-10-10 · Analyzed
7.5KEV1 PoCEPSS 1.000
CVE-2025-31650
Apache Tomcat: DoS via malformed HTTP/2 PRIORITY_UPDATE frame
Published 2025-04-28 · Modified
7.51 PoCEPSS 0.599
CVE-2023-28709
Apache Tomcat: Fix for CVE-2023-24998 is incomplete
Published 2023-05-22 · Modified
7.5EPSS 0.480
CVE-2024-24549
Apache Tomcat: HTTP/2 header handling DoS
Published 2024-03-13 · Modified
7.5EPSS 0.231
CVE-2024-34750
Apache Tomcat: HTTP/2 excess header handling DoS
Published 2024-07-03 · Modified
7.5EPSS 0.046
CVE-2023-46589
Apache Tomcat: HTTP request smuggling via malformed trailer headers
Published 2023-11-28 · Modified
7.5EPSS 0.027
CVE-2023-34981
Apache Tomcat: AJP response header mix-up
Published 2023-06-21 · Modified
7.5EPSS 0.011
CVE-2026-66299
Apache Tomcat: DoS via WebSocket chat example
Published 2026-07-28 · Analyzed
7.5EPSS 0.005
CVE-2026-24734
Apache Tomcat Native, Apache Tomcat: OCSP revocation bypass
Published 2026-02-17 · Modified
7.5EPSS 0.005
CVE-2024-52317
Apache Tomcat: Request/response mix-up with HTTP/2
Published 2024-11-18 · Analyzed
6.5EPSS 0.021
CVE-2026-24733
Apache Tomcat: Security constraint bypass with HTTP/0.9
Published 2026-02-17 · Modified
6.5EPSS 0.005
CVE-2026-34500
Apache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled
Published 2026-04-09 · Analyzed
6.5EPSS 0.005
CVE-2024-23672
Apache Tomcat: WebSocket DoS with incomplete closing handshake
Published 2024-03-13 · Modified
6.3EPSS 0.023
CVE-2023-41080
Apache Tomcat: Open redirect with FORM authentication
Published 2023-08-25 · Modified
6.1EPSS 0.060
CVE-2024-52318
Apache Tomcat: Incorrect JSP tag recycling leads to XSS
Published 2024-11-18 · Analyzed
6.1EPSS 0.017
CVE-2023-45648
Apache Tomcat: Trailer header parsing too lenient
Published 2023-10-10 · Modified
5.3EPSS 0.058
CVE-2023-42795
Apache Tomcat: Failure during request clean-up leads to sensitive data leaking to subsequent requests
Published 2023-10-10 · Modified
5.3EPSS 0.022
CVE-2023-28708
Apache Tomcat: JSESSIONID Cookie missing secure attribute in some configurations
Published 2023-03-22 · Modified
4.3EPSS 0.018