Package impact

java Maven / org.apache.tomcat:tomcat-coyote

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2017-5651 critical 9.8 9.8 9y ago In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processing. If the send file processing completed quickly, … susedebianjavaapache
CVE-2023-44487 high 7.5 9.0 3y ago Important: nodejs:20 security update rockylinuxredhatdebiansuse+6
CVE-2026-29129 high 8.0 2mo ago Apache Tomcat: Configured cipher preference order not preserved susedebianjava
CVE-2026-24880 high 8.0 2mo ago Apache Tomcat has an HTTP Request/Response Smuggling vulnerability susedebianjava
CVE-2025-53506 high 8.0 9mo ago Important: tomcat security update redhatrockylinuxsusedebian+1
CVE-2025-31650 high 8.0 11mo ago Important: tomcat security update archredhatrockylinuxsuse+2
CVE-2024-34750 high 8.0 2y ago Important: tomcat security update redhatrockylinuxsusedebian+1
CVE-2024-24549 high 8.0 2y ago Important: tomcat security and bug fix update redhatsuserockylinuxdebian+1
CVE-2020-13934 high 8.0 4y ago Improper Restriction of Operations within the Bounds of a Memory Buffer in Apache Tomcat archsusedebianjava
CVE-2019-0199 high 8.0 6y ago Apache Tomcat Denial of Service vulnerability susedebianjava
CVE-2025-48989 high 7.5 7.5 9mo ago Important: tomcat security update redhatrockylinuxsusedebian+2
CVE-2016-6816 high 7.1 7.1 9y ago The code in Apache Tomcat 9.0.0.M1 to 9.0.0.M11, 8.5.0 to 8.5.6, 8.0.0.RC1 to 8.0.38, 7.0.0 to 7.0.72, and 6.0.0 to 6.0.47 that parsed the HTTP request line permitted invalid characters. This could b… susedebianjavaapache
CVE-2023-42794 medium 5.5 2y ago Moderate: tomcat security update redhatsusedebianjava
CVE-2023-42795 medium 5.5 2y ago Moderate: tomcat security update redhatsusedebianjava
CVE-2023-28709 medium 5.5 3y ago Moderate: tomcat security and bug fix update redhatsusedebianjava
CVE-2023-24998 medium 5.5 3y ago Moderate: tomcat security and bug fix update redhatarchsusedebian+1
CVE-2020-17527 medium 5.5 4y ago While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream re… archsusedebianjava
CVE-2014-0095 medium 5.0 12y ago Denial of service in Apache Tomcat javaapache
CVE-2014-0075 medium 5.0 12y ago Integer Overflow or Wraparound in Apache Tomcat javaapache
CVE-2026-32990 unknown 2mo ago Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, fro… debianjava
CVE-2026-24734 unknown 3mo ago Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verific… susedebianjavagcp
CVE-2024-52317 unknown 2y ago Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between us… susedebianjava
CVE-2024-21733 unknown 2y ago Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL vers… susedebianjava
CVE-2023-34981 unknown 3y ago A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for th… susedebianjava
CVE-2022-42252 unknown 4y ago If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default f… susedebianjava
CVE-2020-13943 unknown 4y ago If an HTTP/2 client connecting to Apache Tomcat 10.0.0-M1 to 10.0.0-M7, 9.0.0.M1 to 9.0.37 or 8.5.0 to 8.5.57 exceeded the agreed maximum number of concurrent streams for a connection (in violation o… susedebianjava