Package impact

java Maven / org.apache.tomcat.embed:tomcat-embed-core

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2026-43512 critical 9.8 9.8 15d ago Apache Tomcat - Digest authenticator will authenticate any unknown user susedebianjavaapache
CVE-2026-41293 critical 9.8 9.8 15d ago Apache Tomcat - HTTP/2 request headers not validated susedebianjavaapache
CVE-2017-5651 critical 9.8 9.8 9y ago In Apache Tomcat 9.0.0.M1 to 9.0.0.M18 and 8.5.0 to 8.5.12, the refactoring of the HTTP connectors introduced a regression in the send file processing. If the send file processing completed quickly, … susedebianjavaapache
CVE-2025-55754 critical 9.6 9.6 9d ago Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences redhatsusedebianjava+1
CVE-2026-43515 critical 9.1 9.1 15d ago Apache Tomcat - Security constraints not correctly applied susedebianjavaapache
CVE-2017-5648 critical 9.1 9.1 9y ago While investigating bug 60718, it was noticed that some calls to application listeners in Apache Tomcat 9.0.0.M1 to 9.0.0.M17, 8.5.0 to 8.5.11, 8.0.0.RC1 to 8.0.41, and 7.0.0 to 7.0.75 did not use th… susedebianjavaapache
CVE-2023-44487 high 7.5 9.0 3y ago Important: nodejs:20 security update rockylinuxredhatdebiansuse+6
CVE-2025-46701 high 8.0 9d ago Improper Handling of Case Sensitivity vulnerability in Apache Tomcat's GCI servlet allows security constraint bypass of security constraints that apply to the pathInfo component of a URI mapped to th… archredhatsusedebian+1
CVE-2026-29129 high 8.0 2mo ago Apache Tomcat: Configured cipher preference order not preserved susedebianjava
CVE-2026-24880 high 8.0 2mo ago Apache Tomcat has an HTTP Request/Response Smuggling vulnerability susedebianjava
CVE-2025-31651 high 8.0 6mo ago Important: tomcat security update rockylinuxredhatsusedebian+1
CVE-2025-48988 high 8.0 9mo ago Important: tomcat security update archredhatrockylinuxsuse+2
CVE-2025-52520 high 8.0 9mo ago Important: tomcat security update redhatrockylinuxsusedebian+1
CVE-2025-53506 high 8.0 9mo ago Important: tomcat security update redhatrockylinuxsusedebian+1
CVE-2025-49125 high 8.0 9mo ago Important: tomcat security update archredhatrockylinuxsuse+2
CVE-2025-31650 high 8.0 11mo ago Important: tomcat security update archredhatrockylinuxsuse+2
CVE-2024-56337 high 8.0 11mo ago Important: tomcat security update redhatrockylinuxsusedebian+1
CVE-2024-34750 high 8.0 2y ago Important: tomcat security update redhatrockylinuxsusedebian+1
CVE-2024-24549 high 8.0 2y ago Important: tomcat security and bug fix update redhatsuserockylinuxdebian+1
CVE-2023-46589 high 8.0 2y ago Important: tomcat security update redhatrockylinuxsusedebian+1
CVE-2021-24122 high 8.0 5y ago When serving resources from a network location using the NTFS file system, Apache Tomcat versions 10.0.0-M1 to 10.0.0-M9, 9.0.0.M1 to 9.0.39, 8.5.0 to 8.5.59 and 7.0.0 to 7.0.106 were susceptible to … archsusedebianjava
CVE-2019-0199 high 8.0 6y ago Apache Tomcat Denial of Service vulnerability susedebianjava
CVE-2020-9484 high 8.0 6y ago Potential remote code execution in Apache Tomcat archsusedebianjava
CVE-2018-8037 high 8.0 8y ago Important: pki-deps:10.6 security update suserockylinuxdebianjava
CVE-2018-8034 high 8.0 8y ago Important: pki-deps:10.6 security update suserockylinuxdebianjava
CVE-2018-8014 high 8.0 8y ago Important: pki-deps:10.6 security update suserockylinuxdebianjava
CVE-2018-11784 high 8.0 8y ago Important: pki-deps:10.6 security update suserockylinuxdebianjava
CVE-2026-43513 high 7.5 7.5 15d ago Apache Tomcat: LockOutRealm treats user names as case-sensitive susedebianjavaapache
CVE-2026-41284 high 7.5 7.5 15d ago Apache Tomcat: Unbounded read in WebDAV LOCK and PROPFIND handling susedebianjavaapache
CVE-2025-55752 high 7.5 7.5 6mo ago Important: tomcat security update rockylinuxredhatsusedebian+2
CVE-2025-48989 high 7.5 7.5 9mo ago Important: tomcat security update redhatrockylinuxsusedebian+2
CVE-2026-42498 high 7.3 7.3 15d ago Apache Tomcat - WebSocket authentication header exposure susedebianjavaapache
CVE-2025-24813 medium 7.0 1y ago Moderate: tomcat security update redhatrockylinuxsusedebian+1
CVE-2020-1938 medium 7.0 6y ago Apache Tomcat treats Apache JServ Protocol (AJP) connections as having higher trust than, for example, a similar HTTP connection. If such connections are available to an attacker, they can be exploit… suserockylinuxdebianjava
CVE-2024-50379 medium 5.5 11mo ago Moderate: tomcat security update redhatrockylinuxsusedebian+1
CVE-2023-41080 medium 5.5 2y ago Moderate: tomcat security update redhatsusedebianjava
CVE-2023-42795 medium 5.5 2y ago Moderate: tomcat security update redhatsusedebianjava
CVE-2023-45648 medium 5.5 2y ago Moderate: tomcat security update redhatsusedebianjava
CVE-2023-24998 medium 5.5 3y ago Moderate: tomcat security and bug fix update redhatarchsusedebian+1
CVE-2023-28709 medium 5.5 3y ago Moderate: tomcat security and bug fix update redhatsusedebianjava
CVE-2020-1935 medium 5.5 6y ago In Apache Tomcat 9.0.0.M1 to 9.0.30, 8.5.0 to 8.5.50 and 7.0.0 to 7.0.99 the HTTP header parsing code used an approach to end-of-line parsing that allowed some invalid HTTP headers to be parsed as va… rockylinuxdebianjava
CVE-2025-61795 medium 5.3 5.3 7mo ago Apache Tomcat Vulnerable to Improper Resource Shutdown or Release susedebianjavaapache
CVE-2014-0095 medium 5.0 12y ago Denial of service in Apache Tomcat javaapache
CVE-2026-43514 low 3.7 3.7 15d ago Apache Tomcat - AJP secret compared in non-constant time susedebianjavaapache
CVE-2017-12617 unknown 1.5 4y ago When running Apache Tomcat, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it contained would be executed by the serv… susejava
CVE-2017-12615 unknown 1.5 8y ago When running Apache Tomcat on Windows with HTTP PUTs enabled, it is possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code it conta… susejava
CVE-2026-34483 unknown 2mo ago Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 1… susedebianjava
CVE-2026-34487 unknown 2mo ago Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat… susedebianjavagcp
CVE-2026-25854 unknown 2mo ago Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, fro… susedebianjava
CVE-2026-32990 unknown 2mo ago Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, fro… debianjava
CVE-2026-24734 unknown 3mo ago Improper Input Validation vulnerability in Apache Tomcat Native, Apache Tomcat. When using an OCSP responder, Tomcat Native (and Tomcat's FFM port of the Tomcat Native code) did not complete verific… susedebianjavagcp
CVE-2026-24733 unknown 3mo ago Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny… susedebianjava
CVE-2025-66614 unknown 3mo ago Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were… susedebianjava
CVE-2025-49124 unknown 1y ago Untrusted Search Path vulnerability in Apache Tomcat installer for Windows. During installation, the Tomcat installer for Windows used icacls.exe without specifying a full path. This issue affects A… susedebianjava
CVE-2024-52317 unknown 2y ago Incorrect object re-cycling and re-use vulnerability in Apache Tomcat. Incorrect recycling of the request and response used by HTTP/2 requests could lead to request and/or response mix-up between us… susedebianjava
CVE-2024-21733 unknown 2y ago Generation of Error Message Containing Sensitive Information vulnerability in Apache Tomcat.This issue affects Apache Tomcat: from 8.5.7 through 8.5.63, from 9.0.0-M11 through 9.0.43. Other, EOL vers… susedebianjava
CVE-2023-34981 unknown 3y ago A regression in the fix for bug 66512 in Apache Tomcat 11.0.0-M5, 10.1.8, 9.0.74 and 8.5.88 meant that, if a response did not include any HTTP headers no AJP SEND_HEADERS messare woudl be sent for th… susedebianjava
CVE-2022-45143 unknown 3y ago The JsonErrorReportValve in Apache Tomcat 8.5.83, 9.0.40 to 9.0.68 and 10.1.0-M1 to 10.1.1 did not escape the type, message or description values. In some circumstances these are constructed from use… susedebianjava
CVE-2022-42252 unknown 4y ago If Apache Tomcat 8.5.0 to 8.5.82, 9.0.0-M1 to 9.0.67, 10.0.0-M1 to 10.0.26 or 10.1.0-M1 to 10.1.0 was configured to ignore invalid HTTP headers via setting rejectIllegalHeader to false (the default f… susedebianjava
CVE-2008-1947 unknown 4y ago Apache Tomcat Cross-site scripting (XSS) vulnerability java
CVE-2021-25122 unknown 5y ago When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body… susedebianjava
CVE-2021-25329 unknown 5y ago The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikel… susedebianjava
CVE-2019-17569 unknown 6y ago The refactoring present in Apache Tomcat 9.0.28 to 9.0.30, 8.5.48 to 8.5.50 and 7.0.98 to 7.0.99 introduced a regression. The result of the regression was that invalid Transfer-Encoding headers were … debianjava
CVE-2019-12418 unknown 7y ago When Apache Tomcat 9.0.0.M1 to 9.0.28, 8.5.0 to 8.5.47, 7.0.0 and 7.0.97 is configured with the JMX Remote Lifecycle Listener, a local attacker without access to the Tomcat process or configuration f… susedebianjava
CVE-2019-17563 unknown 7y ago When using FORM authentication with Apache Tomcat 9.0.0.M1 to 9.0.29, 8.5.0 to 8.5.49 and 7.0.0 to 7.0.98 there was a narrow window where an attacker could perform a session fixation attack. The wind… susedebianjava
CVE-2019-10072 unknown 7y ago The fix for CVE-2019-0199 was incomplete and did not address HTTP/2 connection window exhaustion on write in Apache Tomcat versions 9.0.0.M1 to 9.0.19 and 8.5.0 to 8.5.40 . By not sending WINDOW_UPDA… susedebianjava
CVE-2019-0221 unknown 7y ago The SSI printenv command in Apache Tomcat 9.0.0.M1 to 9.0.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 echoes user provided data without escaping and is, therefore, vulnerable to XSS. SSI is disabled by… susedebianjava
CVE-2019-0232 unknown 7y ago When running on Windows with enableCmdLineArguments enabled, the CGI Servlet in Apache Tomcat 9.0.0.M1 to 9.0.17, 8.5.0 to 8.5.39 and 7.0.0 to 7.0.93 is vulnerable to Remote Code Execution due to a b… debianjava
CVE-2018-1336 unknown 8y ago An improper handing of overflow in the UTF-8 decoder with supplementary characters can lead to an infinite loop in the decoder causing a Denial of Service. Versions Affected: Apache Tomcat 9.0.0.M9 t… susedebianjava
CVE-2018-1305 unknown 8y ago Security constraints defined by annotations of Servlets in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 were only applied once a Servlet had been loaded. … susedebianjava
CVE-2018-1304 unknown 8y ago The URL pattern of "" (the empty string) which exactly maps to the context root was not correctly handled in Apache Tomcat 9.0.0.M1 to 9.0.4, 8.5.0 to 8.5.27, 8.0.0.RC1 to 8.0.49 and 7.0.0 to 7.0.84 … susedebianjava