Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

9.010.010.111.0201720182019202020212022202320242025202620272028

Недавние уязвимости Tomcat

Количество 1 533

github логотип

GHSA-h6fc-48rj-7qqh

4 месяца назад

Apache Tomcat - Digest authenticator will authenticate any unknown user

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2026-43515

4 месяца назад

Improper Authorization vulnerability when multiple method constraints ...

CVSS3: 9.1
EPSS: Низкий
nvd логотип

CVE-2026-43515

4 месяца назад

Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

CVSS3: 9.1
EPSS: Низкий
debian логотип

CVE-2026-43514

4 месяца назад

Observable Timing Discrepancy vulnerabilitywhen comparing AJP secret i ...

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2026-43514

4 месяца назад

Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

CVSS3: 3.7
EPSS: Низкий
debian логотип

CVE-2026-43513

4 месяца назад

Improper Handling of Case Sensitivity vulnerability in LockOutRealm in ...

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2026-43513

4 месяца назад

Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2026-43512

4 месяца назад

DEPRECATED: Authentication Bypass Issues vulnerability in digest authe ...

CVSS3: 9.8
EPSS: Низкий
nvd логотип

CVE-2026-43512

4 месяца назад

DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0. Older unsupported versions any also be affect Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

CVSS3: 9.8
EPSS: Низкий
debian логотип

CVE-2026-42498

4 месяца назад

Exposure of HTTP Authentication Header to unexpected hosts during WebS ...

CVSS3: 7.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
github логотип
GHSA-h6fc-48rj-7qqh

Apache Tomcat - Digest authenticator will authenticate any unknown user

CVSS3: 9.8
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-43515

Improper Authorization vulnerability when multiple method constraints ...

CVSS3: 9.1
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-43515

Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

CVSS3: 9.1
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-43514

Observable Timing Discrepancy vulnerabilitywhen comparing AJP secret i ...

CVSS3: 3.7
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-43514

Observable Timing Discrepancy vulnerability when comparing AJP secret in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

CVSS3: 3.7
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-43513

Improper Handling of Case Sensitivity vulnerability in LockOutRealm in ...

CVSS3: 7.5
0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-43513

Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from 7.0.0 through 7.0.109. Older unsupported versions may also be affected. Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

CVSS3: 7.5
0%
Низкий
4 месяца назад
debian логотип
CVE-2026-43512

DEPRECATED: Authentication Bypass Issues vulnerability in digest authe ...

CVSS3: 9.8
1%
Низкий
4 месяца назад
nvd логотип
CVE-2026-43512

DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 through 9.0.117, from 8.5.0 through 8.5.100, from before 7.0.0. Older unsupported versions any also be affect Users are recommended to upgrade to version 11.0.22, 10.1.55 or 9.0.118 which fix the issue.

CVSS3: 9.8
1%
Низкий
4 месяца назад
debian логотип
CVE-2026-42498

Exposure of HTTP Authentication Header to unexpected hosts during WebS ...

CVSS3: 7.3
1%
Низкий
4 месяца назад

Уязвимостей на страницу


Поделиться