Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Tomcat

Tomcatконтейнер сервлетов с открытым исходным кодом

Релизный цикл, информация об уязвимостях

Продукт: Tomcat
Вендор: apache

График релизов

9.010.010.111.0201720182019202020212022202320242025202620272028

Недавние уязвимости Tomcat

Количество 1 429

redhat логотип

CVE-2026-24733

5 месяцев назад

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.

CVSS3: 5.3
EPSS: Низкий
redhat логотип

CVE-2025-66614

5 месяцев назад

Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field. The vulnerability only applies if client certificate authentication is only enforced at the Connector. It does not apply if client certificate authentication is enforced at the web ...

CVSS3: 5.3
EPSS: Низкий
fstec логотип

BDU:2026-05102

5 месяцев назад

Уязвимость сервера приложений Apache Tomcat, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 6.5
EPSS: Низкий
fstec логотип

BDU:2026-05103

5 месяцев назад

Уязвимость сервера приложений Apache Tomcat, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.1
EPSS: Низкий
fstec логотип

BDU:2026-05104

5 месяцев назад

Уязвимость компонента OCSP сервера приложений Apache Tomcat, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-wmwf-9ccg-fff5

9 месяцев назад

Apache Tomcat Vulnerable to Relative Path Traversal

CVSS3: 7.5
EPSS: Средний
github логотип

GHSA-vfww-5hm6-hx2j

9 месяцев назад

Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences

CVSS3: 9.6
EPSS: Средний
github логотип

GHSA-hgrr-935x-pq79

9 месяцев назад

Apache Tomcat Vulnerable to Improper Resource Shutdown or Release

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2025-61795

9 месяцев назад

Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memory usage and application load, it was possible that space for the temporary copies of uploaded parts would be filled faster than GC cleared it, leading to a DoS. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.11, from 10.1.0-M1 through 10.1.46, from 9.0.0.M1 through 9.0.109. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.12 or later, 10.1.47 or later or 9.0.110 or later which fixes the issue.

CVSS3: 5.3
EPSS: Низкий
debian логотип

CVE-2025-61795

9 месяцев назад

Improper Resource Shutdown or Release vulnerability in Apache Tomcat. ...

CVSS3: 5.3
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
1
redhat логотип
CVE-2026-24733

Improper Input Validation vulnerability in Apache Tomcat. Tomcat did not limit HTTP/0.9 requests to the GET method. If a security constraint was configured to allow HEAD requests to a URI but deny GET requests, the user could bypass that constraint on GET requests by sending a (specification invalid) HEAD request using HTTP/0.9. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0.M1 through 9.0.112. Older, EOL versions are also affected. Users are recommended to upgrade to version 11.0.15 or later, 10.1.50 or later or 9.0.113 or later, which fixes the issue.

CVSS3: 5.3
0%
Низкий
5 месяцев назад
redhat логотип
CVE-2025-66614

Improper Input Validation vulnerability. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.14, from 10.1.0-M1 through 10.1.49, from 9.0.0-M1 through 9.0.112. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 through 8.5.100. Older EOL versions are not affected. Tomcat did not validate that the host name provided via the SNI extension was the same as the host name provided in the HTTP host header field. If Tomcat was configured with more than one virtual host and the TLS configuration for one of those hosts did not require client certificate authentication but another one did, it was possible for a client to bypass the client certificate authentication by sending different host names in the SNI extension and the HTTP host header field. The vulnerability only applies if client certificate authentication is only enforced at the Connector. It does not apply if client certificate authentication is enforced at the web ...

CVSS3: 5.3
0%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-05102

Уязвимость сервера приложений Apache Tomcat, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 6.5
0%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-05103

Уязвимость сервера приложений Apache Tomcat, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю выполнить произвольный код

CVSS3: 9.1
0%
Низкий
5 месяцев назад
fstec логотип
BDU:2026-05104

Уязвимость компонента OCSP сервера приложений Apache Tomcat, позволяющая нарушителю выполнить произвольный код

CVSS3: 7.5
0%
Низкий
5 месяцев назад
github логотип
GHSA-wmwf-9ccg-fff5

Apache Tomcat Vulnerable to Relative Path Traversal

CVSS3: 7.5
67%
Средний
9 месяцев назад
github логотип
GHSA-vfww-5hm6-hx2j

Apache Tomcat Vulnerable to Improper Neutralization of Escape, Meta, or Control Sequences

CVSS3: 9.6
10%
Средний
9 месяцев назад
github логотип
GHSA-hgrr-935x-pq79

Apache Tomcat Vulnerable to Improper Resource Shutdown or Release

CVSS3: 5.3
1%
Низкий
9 месяцев назад
nvd логотип
CVE-2025-61795

Improper Resource Shutdown or Release vulnerability in Apache Tomcat. If an error occurred (including exceeding limits) during the processing of a multipart upload, temporary copies of the uploaded parts written to disc were not cleaned up immediately but left for the garbage collection process to delete. Depending on JVM settings, application memory usage and application load, it was possible that space for the temporary copies of uploaded parts would be filled faster than GC cleared it, leading to a DoS. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.11, from 10.1.0-M1 through 10.1.46, from 9.0.0.M1 through 9.0.109. The following versions were EOL at the time the CVE was created but are known to be affected: 8.5.0 though 8.5.100. Other, older, EOL versions may also be affected. Users are recommended to upgrade to version 11.0.12 or later, 10.1.47 or later or 9.0.110 or later which fixes the issue.

CVSS3: 5.3
1%
Низкий
9 месяцев назад
debian логотип
CVE-2025-61795

Improper Resource Shutdown or Release vulnerability in Apache Tomcat. ...

CVSS3: 5.3
1%
Низкий
9 месяцев назад

Уязвимостей на страницу


Поделиться